瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求助!!!!求助!!!!!高手进来!!!!

123   3  /  3  页   跳转

求助!!!!求助!!!!!高手进来!!!!

先按上面的做  看看还有什么问题
gototop
 

正在运行的进程
[PID: 460][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 540][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 568][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\Ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4124]
    [C:\WINDOWS\system32\WgaLogon.dll]  [Microsoft Corporation, 1.7.0018.5]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 612][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\AppPatch\AcAdProc.dll]  [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
[PID: 624][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 768][C:\WINDOWS\System32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4124]
    [C:\WINDOWS\System32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2499]
[PID: 796][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 856][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 940][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\wups2.dll]  [Microsoft Corporation, 7.0.6000.374 (winmain(wmbla).070416-2057)]
[PID: 1568][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [F:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [C:\WINDOWS\system32\WPDShServiceObj.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\PortableDeviceTypes.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\xunleibho_v14.dll]  [Thunder Networking Technologies,LTD, 4, 6, 0, 62]
    [e:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [e:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [F:\新建文件夹 (6)\WebThunderBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 2, 10]
    [F:\KuGoo3DownXControl.ocx]  [N/A, ]
    [F:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [C:\WINDOWS\System32\LgdGuard.dll]  [, ]
[PID: 1976][C:\Program Files\Lenovo\幸福一键通\Kbdriver.exe]  [N/A, ]
    [C:\Program Files\Lenovo\幸福一键通\lxkeyled.dll]  [N/A, ]
    [C:\Program Files\Lenovo\幸福一键通\VolumeOsd.dll]  [N/A, ]
    [C:\Program Files\Lenovo\幸福一键通\ScrOSD32.dll]  [N/A, ]
    [C:\Program Files\Lenovo\幸福一键通\tgekb.dll]  [N/A, ]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Lenovo\幸福一键通\XPNyGet.dll]  [N/A, ]
    [F:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 1984][C:\Program Files\Lenovo\幸福一键通\FlyShuttle.exe]  [, 1, 0, 0, 1]
    [C:\Program Files\Lenovo\幸福一键通\CLxUI.dll]  [联想(北京)有限公司, 1, 0, 0, 1]
    [C:\Program Files\Lenovo\幸福一键通\SKOSD.DLL]  [Silitek Corp., 1, 0, 6, 0]
    [C:\Program Files\Lenovo\幸福一键通\SKUtil.DLL]  [Silitek Corp., 1, 0, 9, 0]
    [C:\Program Files\Lenovo\幸福一键通\VolumeOsd.dll]  [N/A, ]
    [C:\Program Files\Lenovo\幸福一键通\ScrOSD32.dll]  [N/A, ]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [F:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 1996][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5.0.19]
    [F:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 2040][C:\WINDOWS\vsnpstd3.exe]  [, 1, 0, 1, 2]
    [F:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 168][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3536]
    [F:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 200][F:\Program Files\Rising\KakaToolBar\runiep.exe]  [Beijing Rising Technology Co., Ltd., 1, 0, 1, 6]
    [F:\Program Files\Rising\KakaToolBar\iep_ctrl.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
    [F:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 292][F:\新建文件夹 (6)\WebThunder.exe]  [深圳市迅雷网络技术有限公司, 1, 8, 4, 130]
    [F:\新建文件夹 (6)\RegisterDll.dll]  [Thunder Networking Technologies,LTD, 2, 13, 4, 58]
    [F:\新建文件夹 (6)\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [F:\新建文件夹 (6)\TaskManager.dll]  [Thunder Networking Technologies,LTD, 1, 1, 1, 24]
    [F:\新建文件夹 (6)\download_interface.dll]  [Thunder Networking Technologies,LTD, 2, 15, 2, 98]
    [F:\新建文件夹 (6)\stlport_vc646.dll]  [STLport Consulting, Inc., 4.6.2003.1031]
    [F:\新建文件夹 (6)\asyn_dns.dll]  [Thunder Networking Technologies,LTD, 2, 15, 2, 98]
    [F:\新建文件夹 (6)\Inmedia\iEmbedShell.dll]  [ , 1, 0, 0, 19]
    [F:\新建文件夹 (6)\InMedia\iEmbed10.dll]  [ , 3, 3, 1, 82]
    [F:\新建文件夹 (6)\CacheServer.dll]  [, 1, 0, 0, 1]
    [F:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [e:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx]  [Adobe Systems, Inc., 9,0,45,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 336][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [F:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 492][C:\Program Files\Messenger\msmsgs.exe]  [Microsoft Corporation, 4.7.3001]
    [F:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 968][C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe]  [, 1.0]
    [F:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 2072][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [F:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 2576][E:\Program Files\Rising\Rav\RsAgent.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
    [E:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [F:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 2676][C:\WINDOWS\msagent\AgentSvr.exe]  [Microsoft Corporation, 2.00.0.3424]
    [F:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 3680][C:\WINDOWS\system32\ntvdm.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [F:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 2004][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\KakaTool.dll]  [Beijing Rising Technology Co., Ltd., 2, 0, 2, 6]
    [F:\新建文件夹 (6)\WebThunderBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 2, 10]
    [C:\WINDOWS\System32\xunleibho_v14.dll]  [Thunder Networking Technologies,LTD, 4, 6, 0, 62]
    [f:\Program Files\Tencent\QQ\QQIEHelper.dll]  [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
    [F:\KuGoo3DownXControl.ocx]  [N/A, ]
    [F:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [e:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx]  [Adobe Systems, Inc., 9,0,45,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\xpsp3res.dll]  [Microsoft Corporation, 5.1.2600.3100 (xpsp_sp2_gdr.070309-0025)]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 2, 0, 0, 1]
    [C:\WINDOWS\system32\dllMergeDict.dll]  [N/A, ]
    [f:\Program Files\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [C:\WINDOWS\system32\KIme.ime]  [金山软件公司, 1, 0, 0, 1]
    [C:\PROGRA~1\COMMON~1\KingSoft\Extract\KSEngine.dll]  [, 1, 0, 0, 1]
    [C:\PROGRA~1\COMMON~1\KingSoft\Extract\xfile.dll]  [N/A, ]
[PID: 1644][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\KakaTool.dll]  [Beijing Rising Technology Co., Ltd., 2, 0, 2, 6]
    [F:\新建文件夹 (6)\WebThunderBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 2, 10]
    [C:\WINDOWS\System32\xunleibho_v14.dll]  [Thunder Networking Technologies,LTD, 4, 6, 0, 62]
    [f:\Program Files\Tencent\QQ\QQIEHelper.dll]  [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
    [F:\KuGoo3DownXControl.ocx]  [N/A, ]
    [F:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [e:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx]  [Adobe Systems, Inc., 9,0,45,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 3956][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\KakaTool.dll]  [Beijing Rising Technology Co., Ltd., 2, 0, 2, 6]
    [F:\新建文件夹 (6)\WebThunderBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 2, 10]
    [C:\WINDOWS\System32\xunleibho_v14.dll]  [Thunder Networking Technologies,LTD, 4, 6, 0, 62]
    [f:\Program Files\Tencent\QQ\QQIEHelper.dll]  [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
    [F:\KuGoo3DownXControl.ocx]  [N/A, ]
    [F:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [e:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx]  [Adobe Systems, Inc., 9,0,45,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 3776][E:\新建文件夹 (8)\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [F:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
gototop
 

不明白你上面写的是什么
gototop
 

如果有摄像头  C:\WINDOWS\vsnpstd3.exe
gototop
 

用sreng
删除启动项目=>注册表
<jtsa><C:\DOCUME~1\user\LOCALS~1\Temp\jtso.exe> [N/A]
<wlsa><C:\DOCUME~1\user\LOCALS~1\Temp\wlso.exe> [N/A]
<wgsa><C:\DOCUME~1\user\LOCALS~1\Temp\wgso.exe> [N/A]
<wmsa><C:\DOCUME~1\user\LOCALS~1\Temp\wmso.exe> [N/A]
<qjsa><C:\DOCUME~1\user\LOCALS~1\Temp\qjso.exe> [N/A]
<rxsa><C:\DOCUME~1\user\LOCALS~1\Temp\rxso.exe> [N/A]
<wdsa><C:\DOCUME~1\user\LOCALS~1\Temp\wdso.exe> [N/A]
<tlsa><C:\DOCUME~1\user\LOCALS~1\Temp\tlso.exe> [N/A]
<dasa><C:\DOCUME~1\user\LOCALS~1\Temp\daso.exe> [N/A]

删除启动项目=>服务
[Distributed Application Client / MOBILL][Stopped/Auto Start]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL,Export 1087><N/A>
[Machine Moniter / Security][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\System32\spted.dll><N/A>
[Windows Help / WinHelp][Stopped/Auto Start]
<C:\WINDOWS\winhlep.exe -NetSata><N/A>

安全模式清空
C:\DOCUME~1\user\LOCALS~1\Temp\

删除文件
C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL
C:\WINDOWS\System32\spted.dll
C:\WINDOWS\winhlep.exe

下个清理流氓软件的软件 清理下..
gototop
 
123   3  /  3  页   跳转
页面顶部
Powered by Discuz!NT