1234   4  /  4  页   跳转

一个瑞星(298$的那个)杀不掉的毒.

[c:\PROGRA~1\iesnap\navpref.dll]  [, 1, 0, 1, 1]
    [C:\Program Files\Tencent\TT\dbghelp.dll]  [Microsoft Corporation, 6.3.0005.1 (DbgBuild.030922-1449)]
    [c:\PROGRA~1\iesnap\navseg.dll]  [, 1, 0, 1, 1]
    [c:\PROGRA~1\iesnap\navneg.dll]  [, 1, 0, 1, 1]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx]  [Macromedia, Inc., 8,0,24,0]
[PID: 2856][C:\Program Files\Rising\AntiSpyware\runiep.exe]  [Beijing Rising Technology Co., Ltd., 1, 0, 1, 6]
    [C:\Program Files\Rising\AntiSpyware\iep_ctrl.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\MsnQun\MSNQUN.dll]  [Msn群开发团队, 1, 0, 0, 2]
    [c:\PROGRA~1\iesnap\navstub.dll]  [, 1, 0, 1, 1]
    [C:\PROGRA~1\dwwv\tjji.dll]  [, 1, 0, 0, 6]
    [C:\PROGRA~1\dwwv\voon.dll]  [ , 1, 0, 0, 6]
[PID: 3392][C:\WINDOWS\system32\MSRundll.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\bofang.dll]  [  , 1, 0, 0, 3]
    [C:\Program Files\MsnQun\MSNQUN.dll]  [Msn群开发团队, 1, 0, 0, 2]
    [c:\PROGRA~1\iesnap\navstub.dll]  [, 1, 0, 1, 1]
    [C:\PROGRA~1\dwwv\tjji.dll]  [, 1, 0, 0, 6]
    [C:\PROGRA~1\dwwv\voon.dll]  [ , 1, 0, 0, 6]
[PID: 5776][C:\WINDOWS\system32\MSRundll.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\bofang.dll]  [  , 1, 0, 0, 3]
    [C:\Program Files\MsnQun\MSNQUN.dll]  [Msn群开发团队, 1, 0, 0, 2]
    [c:\PROGRA~1\iesnap\navstub.dll]  [, 1, 0, 1, 1]
    [C:\PROGRA~1\dwwv\tjji.dll]  [, 1, 0, 0, 6]
    [C:\PROGRA~1\dwwv\voon.dll]  [ , 1, 0, 0, 6]
[PID: 4676][C:\WINDOWS\system32\MSRundll.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\bofang.dll]  [  , 1, 0, 0, 3]
    [C:\Program Files\MsnQun\MSNQUN.dll]  [Msn群开发团队, 1, 0, 0, 2]
    [c:\PROGRA~1\iesnap\navstub.dll]  [, 1, 0, 1, 1]
    [C:\PROGRA~1\dwwv\tjji.dll]  [, 1, 0, 0, 6]
    [C:\PROGRA~1\dwwv\voon.dll]  [ , 1, 0, 0, 6]
[PID: 4420][C:\Documents and Settings\Administrator\桌面\SEng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\Program Files\MsnQun\MSNQUN.dll]  [Msn群开发团队, 1, 0, 0, 2]
    [c:\PROGRA~1\iesnap\navstub.dll]  [, 1, 0, 1, 1]
    [C:\PROGRA~1\dwwv\tjji.dll]  [, 1, 0, 0, 6]
    [C:\PROGRA~1\dwwv\voon.dll]  [ , 1, 0, 0, 6]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

凌晨发的帖子,竟然就那么后面了,顶下,麻烦前辈帮忙了:)
gototop
 

我的扫描结果(见第二页)又沉了,再顶下,盼高手中谢谢!
gototop
 

你得自己起个贴,别这样塞在别人的后面。

这里喜欢帮人的那几个高手,没空翻看。
gototop
 

用 Windows清理助手啊,已经可以清理掉了
www.arswp.com
gototop
 

引用:
【zonhi求助的贴子】前辈,按照你的方法,我已经删掉了,但是有一个文件删不掉
C:\WINDOWS\system32\ieagent.exe
系统提示:此文件正在被使用。
………………



用冰刃删.
冰刃下载
http://www.ttian.net/website/2005/0829/391.html
gototop
 

[usb8028 / usb8028][Running/System Start]
<system32\drivers\usb8028.sys><Microsoft Corporation>
[usb8028x / usb8028x][Running/System Start]
<system32\drivers\usb8028x.sys><Windows System Internal>

都是有了这个!!!!

去看这贴吧:http://forum.ikaka.com/topic.asp?board=28&artid=8298384
gototop
 
1234   4  /  4  页   跳转
页面顶部
Powered by Discuz!NT