瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】各位高手 帮帮我吧 我受不了了 在线等

1234   3  /  4  页   跳转

【求助】各位高手 帮帮我吧 我受不了了 在线等

谢谢大家了  那我明天回去删了那个DLL  文件试试看吧
gototop
 

引用:
【风吹过的树叶的贴子】D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[Rising Web Scan ]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[ActiveMovieControl ]
{05589FA1-C356-11CE-BF01-00AA0055595A} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[C:\Program Files\racer-henan-cnc\rwxre.dll] [Mozilla Foundation, 1.7.3: 2005031010]
[C:\Program Files\racer-henan-cnc\nspr4.dll] [Netscape Communications Corporation, 4.5 Beta]
[C:\Program Files\racer-henan-cnc\xpcom.dll] [Mozilla Foundation, 1.7.3: 2005031010]
[C:\Program Files\racer-henan-cnc\nss3.dll] [Netscape Communications Corporation, 3.9.1]
[C:\Program Files\racer-henan-cnc\softokn3.dll] [Netscape Communications Corporation, 3.9.1]
[C:\Program Files\racer-henan-cnc\gkgfx.dll] [Mozilla Foundation, 1.7.3: 2005031010]
[C:\Program Files\racer-henan-cnc\js3250.dll] [Netscape Communications Corporation, 4.0]
[C:\Program Files\racer-henan-cnc\components\racer_base_comp.dll] [Putian Runway, 2,0,44,83]
[C:\Program Files\racer-henan-cnc\xpcom_compat.dll] [Mozilla Foundation, 1.7.3: 2005031010]
[C:\Program Files\racer-henan-cnc\racer_base.dll] [Putian Runway, 2,0,44,83]
[C:\Program Files\racer-henan-cnc\components\pipnss.dll] [Mozilla Foundation, 1.7.3: 2005031010]
[C:\Program Files\racer-henan-cnc\components\gklayout.dll] [Mozilla Foundation, 1.7.3: 2005031010]
[C:\PROGRA~1\3721\CnsM.dll] [3721, 2.5.1.1003]
比较可疑,期待高手解答
………………
  这个好像是我家网通的登陆客户端
gototop
 

引用:
【loveperday的贴子】[kfkaqgo / kfkaqgo][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\kfkaqgo.sys><N/A>
这个比较可疑。
楼主是QQ问题啊,怪不得QQ下面那么多可疑的DLL文件。但对QQ不熟悉。你用QQ自己的QQ医生检查过么?
………………

用QQ医生检查过  还用瑞星杀过  都没有查出来
gototop
 

引用:
【乐影依翼的贴子】谢谢大家了  那我明天回去删了那个DLL  文件试试看吧
………………

楼主,18楼说的那个驱动也要干掉阿,我说的那个只是你个盗号的家伙,建议你 整个QQ 安装文件删除重新安装拉,密码也得改
gototop
 

[C:\PROGRA~1\3721\CnsM.dll] [3721, 2.5.1.1003]
这个应该是3721的XX工具吧...
D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
这个应该是IE看FLASH的插件...
还是上网搜搜有没有专杀工具吧~
召唤高人
gototop
 

引用:
【subomaoming的贴子】结束QQ后删除F:\QQ\QQAPI.dll
………………

为什么是这个勒?
gototop
 

引用:
【subomaoming的贴子】
楼主,18楼说的那个驱动也要干掉阿,我说的那个只是你个盗号的家伙,建议你 整个QQ 安装文件删除重新安装拉,密码也得改
………………

怎么删除驱动啊?  用什么软件删啊?
gototop
 

以下内容被选中:
    正在运行的进程(包括进程模块信息)


启动项目
注册表
N/A

==================================
启动文件夹
N/A

==================================
服务
N/A

==================================
驱动程序
N/A

==================================
浏览器加载项
N/A

==================================
正在运行的进程
[PID: 584][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1556][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\Unlocker\UnlockerCOM.dll]  [N/A, ]
    [D:\备分\迅雷\ComDlls\XunLeiBHO_007.dll]  [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
[PID: 532][C:\Program Files\Rising\AntiSpyware\runiep.exe]  [Beijing Rising Technology Co., Ltd., 1, 0, 1, 6]
    [C:\Program Files\Rising\AntiSpyware\iep_ctrl.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 800][C:\Program Files\racer-henan-cnc\racer.exe]  [Putian Runway, 2,0,44,83]
    [C:\Program Files\racer-henan-cnc\rwxre.dll]  [Mozilla Foundation, 1.7.3: 2005031010]
    [C:\Program Files\racer-henan-cnc\nspr4.dll]  [Netscape Communications Corporation, 4.5 Beta]
    [C:\Program Files\racer-henan-cnc\xpcom.dll]  [Mozilla Foundation, 1.7.3: 2005031010]
    [C:\Program Files\racer-henan-cnc\nss3.dll]  [Netscape Communications Corporation, 3.9.1]
    [C:\Program Files\racer-henan-cnc\softokn3.dll]  [Netscape Communications Corporation, 3.9.1]
    [C:\Program Files\racer-henan-cnc\gkgfx.dll]  [Mozilla Foundation, 1.7.3: 2005031010]
    [C:\Program Files\racer-henan-cnc\js3250.dll]  [Netscape Communications Corporation, 4.0]
    [C:\Program Files\racer-henan-cnc\components\racer_base_comp.dll]  [Putian Runway, 2,0,44,83]
    [C:\Program Files\racer-henan-cnc\xpcom_compat.dll]  [Mozilla Foundation, 1.7.3: 2005031010]
    [C:\Program Files\racer-henan-cnc\racer_base.dll]  [Putian Runway, 2,0,44,83]
    [C:\Program Files\racer-henan-cnc\components\pipnss.dll]  [Mozilla Foundation, 1.7.3: 2005031010]
    [C:\Program Files\racer-henan-cnc\components\gklayout.dll]  [Mozilla Foundation, 1.7.3: 2005031010]
    [C:\Program Files\racer-henan-cnc\components\jar50.dll]  [Mozilla Foundation, 1.7.3: 2005031010]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\racer-henan-cnc\components\xpcom_compat_c.dll]  [Mozilla Foundation, 1.7.3: 2005031010]
    [C:\Program Files\racer-henan-cnc\components\racer_ad_comp.dll]  [Putian Runway, 2,0,44,83]
    [C:\Program Files\racer-henan-cnc\components\racer_access_dhcpplus.dll]  [Putian Runway, 2,0,44,83]
    [C:\Program Files\racer-henan-cnc\dhcpplus.dll]  [北京润汇科技有限公司, 0, 10, 19, 43]
    [C:\Program Files\racer-henan-cnc\wpcap.dll]  [Politecnico di Torino, 3, 0, 0, 18]
    [C:\Program Files\racer-henan-cnc\pthreadVC.dll]  [N/A, ]
    [C:\Program Files\racer-henan-cnc\packet.dll]  [Politecnico di Torino, 3, 0, 0, 18]
    [C:\Program Files\racer-henan-cnc\components\racer_nss4_comp.dll]  [Putian Runway, 2,0,44,83]
    [C:\Program Files\racer-henan-cnc\nss4.dll]  [北京普天润汇科技有限公司, 1, 0, 0, 3]
[PID: 3648][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\备分\迅雷\ComDlls\XunLeiBHO_007.dll]  [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL]  [Microsoft Corporation, 11.0.5510]
[PID: 2836][D:\SRENG\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]

==================================
文件关联
N/A

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
N/A

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================

gototop
 

这是删除QQAPI。DLL文件后的部分扫描
为什么不显示驱动了? 怎么跟我第一次扫的差了那么多?
是因为没上QQ么?
gototop
 

顶起
gototop
 
1234   3  /  4  页   跳转
页面顶部
Powered by Discuz!NT