瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 跪求高手进来分析我的日志!~~!`谢谢了!~

12   2  /  2  页   跳转

跪求高手进来分析我的日志!~~!`谢谢了!~

Indexing Data / SOCEESe][Stopped/Auto Start]
<C:\WINDOWS\SYSTEM32\RUNDLL2000.EXE C:\WINDOWS\SYSTEM32\WBEM\UETZL.DLL,Export 1087><Microsoft Corporation>

[jsdxib1 / jsdxib16][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\jsdxib16.sys><N/A>
[dcwm / dcwma][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\dcwma.sys><N/A>
[mvaicj0 / mvaicj07][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\mvaicj07.sys><N/A>

gototop
 

删除驱动:
[3WAREDRV / 3WAREDRV][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\3WAREDRV.SYS><N/A>
[3WAREGSM / 3WAREGSM][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\3waregsm.sys><N/A>
[3WDRV100 / 3WDRV100][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\3WDRV100.SYS><N/A>
[cfbegaba / cfbegaba][Stopped/Boot Start]
<\SystemRoot\system32\drivers\cfbegaba.sys><N/A>
[dcwm / dcwma][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\dcwma.sys><N/A>
[EagleNT / EagleNT][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\EagleNT.sys><N/A>
[FTSATA2 / FTSATA2][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\ftsata2.sys><N/A>
[C:\WINDOWS\system32\drivers\IOPort.sys / IOPort][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\IOPort.sys><N/A>
[mvaicj0 / mvaicj07][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\mvaicj07.sys><N/A>
[qqeyns0 / qqeyns03][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\qqeyns03.sys><N/A>
删除文件:
[C:\WINDOWS\system32\dgihgm29.dll] [, 1, 1, 1, 1011]
[C:\WINDOWS\system32\dgihgm29.dll] [, 1, 1, 1, 1011]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\WINDOWS\system32\winhgm29.dll] [, 1, 1, 1, 1032]
修复系统关联
删除HOSTS:
255.0.0.1 www.wg2046.com
255.0.0.1 wg2046.com
gototop
 

漏了这个:
Indexing Data / SOCEESe][Stopped/Auto Start]
<C:\WINDOWS\SYSTEM32\RUNDLL2000.EXE C:\WINDOWS\SYSTEM32\WBEM\UETZL.DLL,Export 1087><Microsoft Corporation>
gototop
 

我代表全家谢谢你,朋友!~
删除文件:
[C:\WINDOWS\system32\dgihgm29.dll] [, 1, 1, 1, 1011]
[C:\WINDOWS\system32\dgihgm29.dll] [, 1, 1, 1, 1011]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\WINDOWS\system32\winhgm29.dll] [, 1, 1, 1, 1032]
这些都是运行进程怎么删除呀?别的我都按照你说的删除了!~
请指教!~~
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT