瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 这么毒呀,这么厉害,老杀不干净,帮帮忙呀

12   2  /  2  页   跳转

这么毒呀,这么厉害,老杀不干净,帮帮忙呀


    [C:\PROGRA~1\jmfi\wsvv.dll]  [, 1, 0, 0, 6]
    [C:\PROGRA~1\jmfi\bexa.dll]  [ , 1, 0, 0, 6]
[PID: 2516][C:\program files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\TENCENT\Adplus\Adplus1.dll]  [Tencent, 4, 4, 1, 14]
    [C:\Program Files\TENCENT\Adplus\SSAddr1.dll]  [Tencent, 4, 4, 2, 22]
    [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\WINDOWS\system32\AcSignIcon.dll]  [Autodesk, 17.0.54.0]
    [D:\Program Files\QQDownload\QQIEHelper01.dll]  [腾讯公司, 1, 1, 0, 5]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\PROGRA~1\jmfi\wsvv.dll]  [, 1, 0, 0, 6]
    [C:\PROGRA~1\jmfi\bexa.dll]  [ , 1, 0, 0, 6]
[PID: 2528][C:\WINDOWS\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\TENCENT\Adplus\Adplus1.dll]  [Tencent, 4, 4, 1, 14]
    [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\PROGRA~1\jmfi\wsvv.dll]  [, 1, 0, 0, 6]
    [C:\PROGRA~1\jmfi\bexa.dll]  [ , 1, 0, 0, 6]
[PID: 2596][C:\WINDOWS\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\TENCENT\Adplus\Adplus1.dll]  [Tencent, 4, 4, 1, 14]
    [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\PROGRA~1\jmfi\wsvv.dll]  [, 1, 0, 0, 6]
    [C:\PROGRA~1\jmfi\bexa.dll]  [ , 1, 0, 0, 6]
[PID: 2608][C:\program files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\TENCENT\Adplus\Adplus1.dll]  [Tencent, 4, 4, 1, 14]
    [C:\Program Files\TENCENT\Adplus\SSAddr1.dll]  [Tencent, 4, 4, 2, 22]
    [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\WINDOWS\system32\AcSignIcon.dll]  [Autodesk, 17.0.54.0]
    [D:\Program Files\QQDownload\QQIEHelper01.dll]  [腾讯公司, 1, 1, 0, 5]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\PROGRA~1\jmfi\wsvv.dll]  [, 1, 0, 0, 6]
    [C:\PROGRA~1\jmfi\bexa.dll]  [ , 1, 0, 0, 6]
[PID: 2740][C:\WINDOWS\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\TENCENT\Adplus\Adplus1.dll]  [Tencent, 4, 4, 1, 14]
    [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\PROGRA~1\jmfi\wsvv.dll]  [, 1, 0, 0, 6]
    [C:\PROGRA~1\jmfi\bexa.dll]  [ , 1, 0, 0, 6]
[PID: 2800][C:\Program Files\Common Files\Microsoft Shared\Web Folders\SVCHOST.EXE]  [N/A, ]
[PID: 2880][C:\Program Files\Ninetowns Corp\iCSP_SM\iProcessAgent.exe]  [ , 1.0.2246.29914]
    [C:\WINDOWS\system32\mscoree.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll]  [Microsoft Corporation, 1.1.4322.2032]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll]  [Microsoft Corporation, 1.1.4322.2032]
    [c:\windows\microsoft.net\framework\v1.1.4322\mscorlib.dll]  [Microsoft Corporation, 1.1.4322.2032]
    [c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_4667e3c1\mscorlib.dll]  [N/A, ]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\Program Files\TENCENT\Adplus\Adplus1.dll]  [Tencent, 4, 4, 1, 14]
    [C:\PROGRA~1\jmfi\wsvv.dll]  [, 1, 0, 0, 6]
    [C:\PROGRA~1\jmfi\bexa.dll]  [ , 1, 0, 0, 6]
    [c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll]  [Microsoft Corporation, 1.1.4322.2032]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_06053c42\system.windows.forms.dll]  [N/A, ]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSCORJIT.DLL]  [Microsoft Corporation, 1.1.4322.2032]
    [c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll]  [Microsoft Corporation, 1.1.4322.2032]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_312830e4\system.dll]  [N/A, ]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\perfcounter.dll]  [Microsoft Corporation, 1.1.4322.2032]
    [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_perf.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll]  [Microsoft Corporation, 1.1.4322.2032]
    [c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll]  [Microsoft Corporation, 1.1.4322.2032]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_ee33a043\system.drawing.dll]  [N/A, ]
    [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2900][C:\Program Files\Welltech\HKBNKeymap\HKBNKeymap.exe]  [, 1, 0, 0, 1]
    [C:\Program Files\Welltech\HKBNKeymap\K10XX.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\TENCENT\Adplus\Adplus1.dll]  [Tencent, 4, 4, 1, 14]
    [C:\PROGRA~1\jmfi\wsvv.dll]  [, 1, 0, 0, 6]
    [C:\PROGRA~1\jmfi\bexa.dll]  [ , 1, 0, 0, 6]
    [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2964][C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\Program Files\Microsoft SQL Server\80\Tools\Binn\W95SCM.dll]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\Program Files\Microsoft SQL Server\80\Tools\Binn\SQLSVC.dll]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\WINDOWS\system32\odbcbcp.dll]  [Microsoft Corporation, 2000.085.1117.00 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Microsoft SQL Server\80\Tools\Binn\SQLRESLD.dll]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\Program Files\Microsoft SQL Server\80\Tools\Binn\Resources\2052\SQLSVC.RLL]  [Microsoft Corporation, 2000.080.0194.00]
gototop
 


    [C:\Program Files\Microsoft SQL Server\80\Tools\Binn\Resources\2052\sqlmangr.RLL]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\Program Files\TENCENT\Adplus\Adplus1.dll]  [Tencent, 4, 4, 1, 14]
    [C:\PROGRA~1\jmfi\wsvv.dll]  [, 1, 0, 0, 6]
    [C:\PROGRA~1\jmfi\bexa.dll]  [ , 1, 0, 0, 6]
    [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\system32\KSVSvc.dll]  [N/A, ]
[PID: 3112][C:\Program Files\flvplayer\flvplayer.exe]  [N/A, ]
    [C:\Program Files\TENCENT\Adplus\Adplus1.dll]  [Tencent, 4, 4, 1, 14]
    [C:\PROGRA~1\jmfi\wsvv.dll]  [, 1, 0, 0, 6]
    [C:\PROGRA~1\jmfi\bexa.dll]  [ , 1, 0, 0, 6]
    [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 3116][C:\Documents and Settings\Bluewater\桌面\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\Program Files\TENCENT\Adplus\Adplus1.dll]  [Tencent, 4, 4, 1, 14]
    [C:\PROGRA~1\jmfi\wsvv.dll]  [, 1, 0, 0, 6]
    [C:\PROGRA~1\jmfi\bexa.dll]  [ , 1, 0, 0, 6]
    [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\system32\KSVSvc.dll]  [N/A, ]
[PID: 3124][D:\Program Files\QQ2007\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [D:\Program Files\QQ2007\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\QQ2007\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\QQ2007\BasicCtrlDll.dll]  [Tencent, 7, 0, 101, 80]
    [D:\Program Files\QQ2007\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\Program Files\TENCENT\Adplus\Adplus1.dll]  [Tencent, 4, 4, 1, 14]
    [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\PROGRA~1\jmfi\wsvv.dll]  [, 1, 0, 0, 6]
    [C:\PROGRA~1\jmfi\bexa.dll]  [ , 1, 0, 0, 6]
    [D:\Program Files\QQ2007\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [D:\Program Files\QQ2007\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [D:\Program Files\QQ2007\QQAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [D:\Program Files\QQ2007\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [D:\Program Files\QQ2007\LoginCtrl.dll]  [N/A, ]
    [D:\Program Files\QQ2007\LoginCtrlRes.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\KSVSvc.dll]  [N/A, ]
    [D:\Program Files\QQ2007\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [D:\Program Files\QQ2007\WizardCtrl.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\QQ2007\QQMainFrame.dll]  [N/A, ]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 3172][C:\program files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\TENCENT\Adplus\Adplus1.dll]  [Tencent, 4, 4, 1, 14]
    [C:\Program Files\TENCENT\Adplus\SSAddr1.dll]  [Tencent, 4, 4, 2, 22]
    [C:\PROGRA~1\jmfi\wsvv.dll]  [, 1, 0, 0, 6]
    [C:\PROGRA~1\jmfi\bexa.dll]  [ , 1, 0, 0, 6]
    [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\WINDOWS\system32\AcSignIcon.dll]  [Autodesk, 17.0.54.0]
    [D:\Program Files\QQDownload\QQIEHelper01.dll]  [腾讯公司, 1, 1, 0, 5]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [D:\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
    [D:\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
    [D:\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
    [D:\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
    [D:\prkernel.ppl]  [Kaspersky Lab, 6.0.0.299]
    [d:\nfio.ppl]  [Kaspersky Lab, 6.0.0.299]
    [d:\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.0.299]
    [D:\basegui.dll]  [Kaspersky Lab, 6.0.0.300]
[PID: 3236][C:\WINDOWS\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\TENCENT\Adplus\Adplus1.dll]  [Tencent, 4, 4, 1, 14]
    [C:\PROGRA~1\jmfi\wsvv.dll]  [, 1, 0, 0, 6]
    [C:\PROGRA~1\jmfi\bexa.dll]  [ , 1, 0, 0, 6]
    [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 3320][C:\program files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\TENCENT\Adplus\Adplus1.dll]  [Tencent, 4, 4, 1, 14]
    [C:\Program Files\TENCENT\Adplus\SSAddr1.dll]  [Tencent, 4, 4, 2, 22]
    [C:\PROGRA~1\jmfi\wsvv.dll]  [, 1, 0, 0, 6]
    [C:\PROGRA~1\jmfi\bexa.dll]  [ , 1, 0, 0, 6]
    [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\WINDOWS\system32\AcSignIcon.dll]  [Autodesk, 17.0.54.0]
    [D:\Program Files\QQDownload\QQIEHelper01.dll]  [腾讯公司, 1, 1, 0, 5]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [D:\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
    [D:\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
    [D:\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 3328][C:\Program Files\Common Files\Microsoft Shared\Web Folders\SVCHOST.EXE]  [N/A, ]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================



HOSTS 文件
127.0.0.1      localhost
127.0.0.1      mmm.caifu18.net
127.0.0.1      www.18dmm.com
127.0.0.1      d.qbbd.com
127.0.0.1      www.5117music.com
127.0.0.1      www.union123.com
127.0.0.1      www.wu7x.cn
127.0.0.1      www.54699.com
127.0.0.1      www1.6tan.com
127.0.0.1      www2.6tan.com
127.0.0.1      www.97725.com
127.0.0.1      down.97725.com
127.0.0.1      ip.315hack.com
127.0.0.1      ip.54liumang.com
127.0.0.1      www.41ip.com
127.0.0.1      xulao.com
127.0.0.1      www.heixiou.com
127.0.0.1      www.9cyy.com
127.0.0.1      www.hunll.com
127.0.0.1      www.down.hunll.com
127.0.0.1      do.77276.com
127.0.0.1      www.baidulink.com
127.0.0.1      adnx.yygou.cn
127.0.0.1      222.73.220.45
127.0.0.1      www.f5game.com
127.0.0.1      www.guazhan.cn
127.0.0.1      wm,103715.com
127.0.0.1      www.my6688.cn
127.0.0.1      i.96981.com
127.0.0.1      d.77276.com
127.0.0.1      www1.cw988.cn
127.0.0.1      cool.47555.com
127.0.0.1      www.asdwc.com
127.0.0.1      55880.cn
127.0.0.1      61.152.169.234
127.0.0.1      cc.wzxqy.com
127.0.0.1      www.54699.com
127.0.0.1      t.gcuj.com
127.0.0.1      www.puma163.com
127.0.0.1      ceoww.com
127.0.0.1      boolom.com
127.0.0.1      adult-novel.cn
127.0.0.1      ll.chinasese.net
127.0.0.1      www.tellumore.com
127.0.0.1      www.o1wg.com
127.0.0.1      www.qq756.com
127.0.0.1      ll.chinasese.net

==================================
API HOOK
RVA  错误: LoadLibraryA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF6B2FB25)
RVA  错误: LoadLibraryExA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF6B2FD67)
RVA  错误: LoadLibraryExW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF6B2FF0B)
RVA  错误: LoadLibraryW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF6B2FC49)
RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: Dest Addr: 0xF6B2FE8F)

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

救命啦!! 很急的。 现在系统变得很慢。老是提示有病毒,似乎杀不完的。
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT