瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 请各位大虾帮忙杀死这该死的病毒啦!万分感谢!

123   2  /  3  页   跳转

请各位大虾帮忙杀死这该死的病毒啦!万分感谢!

(xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 2, 0, 0, 0]
    [C:\WINDOWS\system32\dllMergeDict.dll]  [N/A, N/A]
    [d:\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 2]
    [C:\WINDOWS\downlo~1\Uexf.dll]  [Tencent, 4, 4, 2, 21]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [C:\PROGRA~1\3721\alrex.dll]  [, 1, 0, 1, 1001]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [d:\3721\ske\contmenu.dll]  [N/A, N/A]
    [C:\PROGRA~1\3721\autolive.dll]  [, 1, 1, 8, 1327]
    [C:\PROGRA~1\3721\alLiveEx.dll]  [ , 1, 0, 3, 1006]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yalive.dll]  [yahoo! china, 3, 5, 9, 1111]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [Yahoo! China, 3, 0, 2, 1011]
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  [北京三七二一科技有限公司, 2, 5, 0, 2]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yclickon.dll]  [YAHOO Corporation Limited, 3, 0, 4, 1005]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 1372][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1572][C:\WINDOWS\system32\Rundll32.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 2]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 2, 0, 0, 0]
    [C:\WINDOWS\system32\dllMergeDict.dll]  [N/A, N/A]
    [d:\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [C:\WINDOWS\DOWNLO~1\CnsMinIO.dll]  [北京三七二一科技有限公司, 2, 5, 0, 3]
    [C:\WINDOWS\DOWNLO~1\cnsio.dll]  [北京三七二一科技有限公司, 2, 5, 0, 2]
    [C:\WINDOWS\DOWNLO~1\CnsMinEx.dll]  [国风因特软件(北京)有限公司, 2, 5, 0, 2]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 2028][C:\WINDOWS\system32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.10.8198]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 2, 0, 0, 0]
    [C:\WINDOWS\system32\dllMergeDict.dll]  [N/A, N/A]
    [d:\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
[PID: 144][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 252][C:\WINDOWS\system32\tlntsvr.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1116][C:\WINDOWS\system32\rundll32.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 2]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 2, 0, 0, 0]
    [C:\WINDOWS\system32\dllMergeDict.dll]  [N/A, N/A]
    [d:\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [C:\PROGRA~1\3721\autolive.dll]  [, 1, 1, 8, 1327]
    [C:\PROGRA~1\3721\notifier.dll]  [, 1, 0, 0, 5]
    [C:\PROGRA~1\3721\alLiveEx.dll]  [ , 1, 0, 3, 1006]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 1140][C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 2]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 2, 0, 0, 0]
    [C:\WINDOWS\system32\dllMergeDict.dll]  [N/A, N/A]
    [d:\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yalive.dll]  [yahoo! china, 3, 5, 9, 1111]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [Yahoo! China, 3, 0, 2, 1011]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\ynotifier.dll]  [yahoo! china, 3, 0, 2, 1002]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 1208][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 2]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 2, 0, 0, 0]
    [C:\WINDOWS\system32\dllMergeDict.dll]  [N/A, N/A]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [d:\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 1816][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180
gototop
 

(xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 2]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 2, 0, 0, 0]
    [C:\WINDOWS\system32\dllMergeDict.dll]  [N/A, N/A]
    [d:\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 2324][C:\Program Files\ChinaNet\VnetClient.exe]  [, 2006, 10, 11, 9]
    [C:\Program Files\ChinaNet\Communicate.dll]  [GDCN, 2006, 2, 15, 1]
    [C:\Program Files\ChinaNet\DialModule.dll]  [GDCN, 2006, 11, 20, 10]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 2]
    [C:\PROGRA~1\ChinaNet\CLIENT~1.DLL]  [, 2004, 2, 28, 1]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 2, 0, 0, 0]
    [C:\WINDOWS\system32\dllMergeDict.dll]  [N/A, N/A]
    [d:\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [C:\PROGRA~1\ChinaNet\PLUGIN~1.OCX]  [, 2006, 6, 2, 14]
    [C:\PROGRA~1\ChinaNet\sign.dll]  [0, 2004, 12, 1, 1]
    [C:\Program Files\ChinaNet\SysPlug\8432d5a0-a09d-41bc-87c1-b312d97192f5\VnetOnlineBusinessAutoLogin.dll]  [, 2006, 11, 19, 21]
    [C:\PROGRA~1\ChinaNet\WEBPLU~1.DLL]  [, 2005, 8, 18, 1]
    [C:\Program Files\ChinaNet\SysPlug\93d07ada-d3ac-485a-85eb-12ca3cee8375\Vnetsafe114.DLL]  [, 1, 0, 0, 1]
    [C:\PROGRA~1\ChinaNet\ADVERT~1.OCX]  [, 2006, 10, 19, 16]
    [C:\PROGRA~1\ChinaNet\VnetBs.ocx]  [, 2004, 11, 18, 1]
    [C:\PROGRA~1\ChinaNet\VnetSkin.ocx]  [GDDC, 2006, 9, 6, 15]
    [C:\PROGRA~1\ChinaNet\DialogStyle.dll]  [, 1, 0, 0, 1]
    [C:\PROGRA~1\ChinaNet\BDSearch.ocx]  [gdcn, 2006, 12, 13, 16]
    [C:\PROGRA~1\ChinaNet\PageFram.ocx]  [Workgroup, 2006, 12, 11, 17]
    [C:\PROGRA~1\ChinaNet\ACCOUN~1.OCX]  [Workgroup, 2006, 10, 31, 16]
    [C:\PROGRA~1\ChinaNet\AccountMgr.dll]  [, 2006, 10, 30, 16]
    [C:\PROGRA~1\ChinaNet\Gif89a.dll]  [, 2005, 6, 21, 1]
    [C:\PROGRA~1\ChinaNet\NOTIFY~1.OCX]  [Workgroup, 2006, 9, 15, 16]
    [C:\PROGRA~1\ChinaNet\IcosBar.ocx]  [Workgroup, 2006, 9, 25, 9]
    [C:\PROGRA~1\ChinaNet\Timer.ocx]  [, 2006, 9, 8, 17]
    [C:\PROGRA~1\ChinaNet\PLUGIN~2.OCX]  [, 2006, 4, 4, 1]
    [C:\PROGRA~1\ChinaNet\NEWMES~1.DLL]  [, 2006, 12, 26, 9]
    [C:\PROGRA~1\ChinaNet\PassCtrl.dll]  [GDCN, 2006, 3, 1, 16]
    [C:\WINDOWS\system32\wpcap.dll]  [Politecnico di Torino, 3, 0, 0, 18]
    [C:\WINDOWS\system32\pthreadVC.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\packet.dll]  [Politecnico di Torino, 3, 0, 0, 18]
    [C:\PROGRA~1\ChinaNet\PlugPush.dll]  [, 2004, 12, 21, 1]
    [C:\PROGRA~1\ChinaNet\ALLINT~1.DLL]  [, 2006, 11, 20, 11]
    [C:\PROGRA~1\ChinaNet\VNETLO~1.OCX]  [, 2005, 10, 9, 1]
    [C:\PROGRA~1\ChinaNet\StatNum.dll]  [, 2006, 3, 1, 1]
    [C:\PROGRA~1\ChinaNet\VNETON~1.OCX]  [, 2005, 3, 2, 1]
    [C:\PROGRA~1\ChinaNet\ALLFUN~1.DLL]  [GDCN, 2006, 12, 26, 9]
    [C:\PROGRA~1\ChinaNet\VnetOptLog.dll]  [ , 2006, 9, 18, 10]
    [C:\PROGRA~1\ChinaNet\Favorite.ocx]  [, 2006, 12, 26, 10]
    [C:\PROGRA~1\ChinaNet\VNETSE~1.OCX]  [, 2006, 10, 31, 16]
    [C:\PROGRA~1\ChinaNet\DlgSkin.ocx]  [, 2006, 8, 29, 15]
    [C:\Program Files\ChinaNet\Base64.dll]  [N/A, N/A]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 1612][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [C:\PROGRA~1\3721\scrblock.dll]  [3721, 2.5.0.1002]
    [C:\PROGRA~1\3721\alrex.dll]  [, 1, 0, 1, 1001]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll]  [Yahoo! China, 3, 0, 3, 1004]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 2]
    [C:\WINDOWS\DOWNLO~1\CnsHint.dll]  [3721, 2, 5, 0, 2]
    [C:\PROGRA~1\3721\autolive.dll]  [, 1, 1, 8, 1327]
    [C:\PROGRA~1\3721\alLiveEx.dll]  [ , 1, 0, 3, 1006]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yalive.dll]  [yahoo! china, 3, 5, 9, 1111]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [Yahoo! China, 3, 0, 2, 1011]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 2, 0, 0, 0]
    [C:\WINDOWS\system32\dllMergeDict.dll]  [N/A, N/A]
    [d:\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [C:\WINDOWS\DOWNLO~1\cnsplus.dll]  [3721, 2, 5, 0, 2]
    [D:\Thunder5\ComDlls\XunLeiBHO_007.dll]  [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  [北京三七二一科技有限公司, 2, 5, 0, 2]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll]  [Yahoo! China, 3, 0, 8, 1010]
    [C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll]  [yahoo! china, 3, 0, 5, 1007]
    [c:\PROGRA~1\chinanet\VNETTR~1.DLL]  [, 2005, 4, 6, 1]
    [c:\PROGRA~1\chinanet\Communicate.dll]  [GDCN, 2006, 2, 15, 1]
    [C:\PROGRA~1\ChinaNet\CLIENT~1.DLL]  [, 2004, 2, 28, 1]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL]  [yahoo! china, 3, 0, 3, 1003]
    [C:\WINDOWS\system32\ssup.dll]  [TENCENT, 4, 4, 3, 30]
    [D:\KuGoo3\KuGoo3DownXControl.ocx]  [N/A, N/A]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yassist.dll]  [Yahoo! China, 3, 1, 6, 1021]
    [C:\WINDOWS\DOWNLO~1\CnsMinIO.dll]  [北京三七二一科技有限公司, 2, 5, 0, 3]
    [C:\WINDOWS\DOWNLO~1\cnsio.dll]  [北京三七二一科技有限公司, 2, 5, 0, 2]
    [C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll]  [yahoo! china, 3, 3, 3, 1094]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ysearch.dll]  [Yahoo! China, 3, 1, 8, 1018]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasnoad.dll]  [yahoo! china, 3, 0, 3, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yzsNetProto.dll]  [Yahoo! China, 3, 0, 2, 1003]
    [C:\Program Files\Yahoo!\Assistant\Assist\yrss.dll]  [Yahoo! China, 3, 0, 4, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yaswiper.dll]  [Yahoo! China, 3, 0, 5, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasiesec.dll]  [Yahoo! China, 3, 0, 5, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YSETTI~1.DLL]  [yahoo! china, 3, 1, 4, 1025]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ymailp.dll]  [Yahoo! China, 3, 0, 5, 1011]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ymyweb.dll]  [Yahoo! China, 3, 0, 3, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yclickon.dll]  [YAHOO Corporation Limited, 3, 0, 4, 1005]
    [c:\progra~1\yahoo!\assist~1\assist\yadfil~1.dll]  [Yahoo! China, 3, 0, 2, 1003]
    [C:\PROGRA~1\yahoo!\assistant\Shell\yAssecblk.dll]  [Yahoo! China, 3, 1, 8, 1026]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yoptimum.dll]  [Yahoo! China, 3, 0, 2, 1006]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrepair.dll]  [Yahoo! China, 3, 0, 9, 1012]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yxpstyle.dll]  [Yahoo! China, 3, 0, 1, 1001]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [C:\WINDOWS\system32\kakatool.dll]  [Beijing Rising Technology Co., Ltd., 2, 0, 2, 6]
    [D:\Thunder5\ComDlls\ThunderAgent_007.dll]  [Thunder Networking Technologies,LTD, 5, 0, 1, 14]
[PID: 3892][C:\Program Files\Rising\AntiSpyware\runiep.exe]  [Beijing Rising Technology Co., Ltd., 1, 0, 1, 6]
    [C:\Program Files\Rising\AntiSpyware\iep_ctrl.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 2]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 2, 0, 0, 0]
    [C:\WINDOWS\system32\dllMergeDict.dll]  [N/A, N/A]
    [d:\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
[PID: 3092][E:\安装文件\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 2]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 2, 0, 0, 0]
    [C:\WINDOWS\system32\dllMergeDict.dll]  [N/A, N/A]
    [d:\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
gototop
 

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
[C:\]
[AutoRun]
open=svchost.exe /start
shellexecute=svchost.exe /start
shell\打开(&O)\command=svchost.exe /start
[D:\]
[AutoRun]
open=svchost.exe /start
shellexecute=svchost.exe /start
shell\打开(&O)\command=svchost.exe /start
[E:\]
[AutoRun]
open=svchost.exe /start
shellexecute=svchost.exe /start
shell\打开(&O)\command=svchost.exe /start
[F:\]
[AutoRun]
open=svchost.exe /start
shellexecute=svchost.exe /start
shell\打开(&O)\command=svchost.exe /start

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
N/A

==================================


[/CODE]
gototop
 

终于发完,请大虾们看看
gototop
 

3721,yahoo助手,搜狐插件,要删的东西太多了,建议卸载3721,yahoo助手,搜狐插件,SOGOU.
gototop
 

卸载也解决不了问题啊?卸了之后又怎样啊?
gototop
 

运行sreng2启动项目,注册表删除
<load><C:\WINDOWS\system32\dllcache\rund1132.exe> [广州大学华软软件学院05软件开发05班 By Amoeba]
启动项目,驱动程序删除
[R2A / R2A][Stopped/Disabled]
<\??\C:\WINDOWS\system32a2.sys><N/A>
[mhkcjiq / mhkcjiq][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\mhkcjiq.sys><N/A>
安全模式下删除
C:\WINDOWS\system32\dllcache\rund1132.exe
C:\WINDOWS\system32a2.sys
C:\WINDOWS\System32\drivers\mhkcjiq.sys
右健打开各硬盘分区删除svchost.exe,Autorun.inf
整页流氓,晕死了……
gototop
 

引用:
【pibo的贴子】3721,yahoo助手,搜狐插件,要删的东西太多了,建议卸载3721,yahoo助手,搜狐插件,SOGOU.
………………


不懂不要出来害人..

1. 杀毒前关闭系统还原(Win2000系统可以忽略):右键 我的电脑 ,属性,系统还原,在所有驱动器上关闭系统还原 打勾即可。
清除IE的临时文件:打开IE 点工具-->Internet选项 : Internet临时文件,点“删除文件”按钮 ,将 删除所有脱机内容 打勾,点确定删除。
2.将下面注册表键值删除:
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><C:\WINDOWS\system32\dllcache\rund1132.exe> [广州大学华软软件学院05软件开发05班 By Amoeba]

3.用PowerRMV(勾选杀灭文件再生成)删除下面文件:
C:\WINDOWS\system32a2.sys>
C:\WINDOWS\System32\drivers\mhkcjiq.sys>
C:\WINDOWS\system32\dllcache\rund1132.exe
C:\WINDOWS\System32\drivers\c24363853.sys
C:\WINDOWS\System32\drivers\c12990359.sys
C:\WINDOWS\system32\drivers\mbgcdgq.sys
x:\autorun.inf
x:\svchost.exe
注: (x:为所有盘符)
4.删除下面服务
c12990359 / c12990359][Stopped/Boot Start]
<\SystemRoot\System32\drivers\c12990359.sys>
[c24363853 / c24363853][Stopped/Boot Start]
<\SystemRoot\System32\drivers\c24363853.sys>
5.删除下面驱动程序
[kdmfjhs / kdmfjhs][Running/System Start]
<2 - 系统找不到指定的文件。
><N/A>
[mbgcdgq / mbgcdgq][Running/Boot Start]
<\SystemRoot\system32\drivers\mbgcdgq.sys><>
R2A / R2A][Stopped/Disabled]
<\??\C:\WINDOWS\system32a2.sys><N/A>
[mhkcjiq / mhkcjiq][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\mhkcjiq.sys><N/A>

PS:建议将3721和搜狗卸载掉..
gototop
 

干掉
<load><C:\WINDOWS\system32\dllcache\rund1132.exe> [广州大学华软软件学院05软件开发05班 By Amoeba]
[C:\WINDOWS\system32\dllMergeDict.dll] [N/A, N/A]

干掉每个盘上的
Autorun.inf
svchost.exe

gototop
 

橙色八月还是维金病毒,可以用专杀查下,如果没有,就可能是其他病毒,一步步来
gototop
 
123   2  /  3  页   跳转
页面顶部
Powered by Discuz!NT