12   2  /  2  页   跳转

【求助】大虾们来看看啊有图

正在运行的进程
[PID: 492][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 572][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 600][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.1557 (xpsp2_gdr.040517-1325)]
    [C:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
    [C:\WINDOWS\system32\Ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4123]
    [C:\WINDOWS\system32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 644][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 656][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 804][C:\WINDOWS\System32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4123]
    [C:\WINDOWS\System32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2499]
[PID: 840][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 920][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
    [C:\WINDOWS\System32\wups.dll]  [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[PID: 1000][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1052][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1316][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4123]
    [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2499]
[PID: 1384][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [C:\WINDOWS\System32\mh104.dll]  [N/A, ]
    [C:\WINDOWS\System32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\AVPSrv.dll]  [N/A, ]
    [d:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [c:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [F:\Program Files\Thunder Network\WebThunder\WebThunderBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 2, 10]
    [F:\Thunder\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.0.7]
    [F:\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 2, 10]
    [F:\Thunder\Components\ResWorker\DsBho_00.dll]  [, 1, 0, 0, 4]
    [F:\Thunder\Components\ResWorker\DataProcessor_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 6]
    [F:\360SAF~1.2\safemon\safemon.dll]  [, 3, 5, 0, 1001]
[PID: 448][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3510]
[PID: 368][C:\WINDOWS\System32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1324][F:\Program Files\Maxthon\Maxthon.exe]  [Maxthon International Ltd., 1, 5, 9, 30]
    [F:\Program Files\Maxthon\maxzlib.dll]  [ , 1, 0, 0, 2]
    [C:\WINDOWS\System32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
    [C:\WINDOWS\System32\msdebug.dll]  [N/A, ]
    [C:\WINDOWS\System32\RemoteDbg.dll]  [N/A, ]
    [C:\WINDOWS\System32\windhcp.ocx]  [N/A, ]
    [F:\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 2, 10]
    [F:\Thunder\Components\ResWorker\DsBho_00.dll]  [, 1, 0, 0, 4]
    [F:\Thunder\Components\ResWorker\DataProcessor_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 6]
    [C:\WINDOWS\System32\odbcbcp.dll]  [Microsoft Corporation, 2000.081.9042.00]
    [F:\Program Files\Maxthon\Services\RealTime\real_time.dll]  [, 1, 0, 0, 1]
    [c:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\System32\AVPSrv.dll]  [N/A, ]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1176][D:\Program Files\Tencent\QQ\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [D:\Program Files\Tencent\QQ\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQ\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQ\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 160]
    [D:\Program Files\Tencent\QQ\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\WINDOWS\System32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
    [C:\WINDOWS\System32\msdebug.dll]  [N/A, ]
    [C:\WINDOWS\System32\RemoteDbg.dll]  [N/A, ]
    [C:\WINDOWS\System32\windhcp.ocx]  [N/A, ]
    [D:\Program Files\Tencent\QQ\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [D:\Program Files\Tencent\QQ\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [D:\Program Files\Tencent\QQ\QQAPI.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQ\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQ\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 3, 2, 1]
    [D:\Program Files\Tencent\QQ\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [C:\WINDOWS\System32\AVPSrv.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQ\WizardCtrl.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQ\QQMainFrame.dll]  [N/A, ]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\Program Files\Tencent\QQ\CQQApplication.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\NewSkin.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQ\HostingMgr.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQ\CameraDll.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQ\MailSummary.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQ\QQSpace.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQ\vbscript.dll]  [Microsoft Corporation, 5.6.0.7426]
    [C:\WINDOWS\System32\msdmo.dll]  [, ]
    [D:\Program Files\Tencent\QQ\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQ\GroupLive.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\QQSysMsgMng.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQ\QQPlugin.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQ\QRingMng.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQ\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [D:\Program Files\Tencent\QQ\QQAvatar.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [D:\Program Files\Tencent\QQ\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [D:\Program Files\Tencent\QQ\QQPet.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQ\QQAllInOne.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\SCCore.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\QQCustomFace.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\gdiplus.dll]  [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\System32\msadp32.acm]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [D:\Program Files\Tencent\QQ\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
    [D:\Program Files\Tencent\QQ\QQSceneMng.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\BQQApplication.dll]  [N/A, ]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [D:\Program Files\Tencent\QQ\CommercesMng.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQ\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [D:\Program Files\Tencent\QQ\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 200]
    [D:\Program Files\Tencent\QQ\GroupConnection.dll]  [Tencent, 5, 0, 202, 170]
    [D:\Program Files\Tencent\QQ\QQPhoneHelper.dll]  [腾讯科技(深圳)有限公司, 2, 1, 9, 93]
[PID: 1192][F:\TDdownload\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\WINDOWS\System32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
    [C:\WINDOWS\System32\msdebug.dll]  [N/A, ]
    [C:\WINDOWS\System32\RemoteDbg.dll]  [N/A, ]
    [C:\WINDOWS\System32\windhcp.ocx]  [N/A, ]
    [C:\WINDOWS\System32\AVPSrv.dll]  [N/A, ]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
N/A

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

对了,还有瑞星监控的那个小雨伞也不见了
gototop
 

<regtangtang><C:\WINDOWS\System32\aa.exe> [N/A]
<Microsoft Autorun4><C:\WINDOWS\System32\dllhost32.exe> []
<AVPSrv><C:\WINDOWS\AVPSrv.exe> []
<wosa><C:\DOCUME~1\lkx\LOCALS~1\Temp\woso.exe> [N/A]
<rxsa><C:\DOCUME~1\lkx\LOCALS~1\Temp\rxso.exe> [N/A]
<qjsa><C:\DOCUME~1\lkx\LOCALS~1\Temp\qjso.exe> [N/A]
<tlsa><C:\DOCUME~1\lkx\LOCALS~1\Temp\tlso.exe> [N/A]
<dasa><C:\DOCUME~1\lkx\LOCALS~1\Temp\daso.exe> [N/A]
<wlsa><C:\DOCUME~1\lkx\LOCALS~1\Temp\wlso.exe> [N/A]
<wgsa><C:\DOCUME~1\lkx\LOCALS~1\Temp\wgso.exe> [N/A]
<?{0CD68AC9-FF63-3E61-626B-B663E62F6236}><> [N/A]
<?{0EA66AD2-CF26-2E23-532B-B292E22F3266}><> [N/A]
<{0EA66AD2-CF26-2E23-532B-B292E22F3266}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\NewTemp.dll> [N/A]
<{0EA12C16-CDEF-6AC1-236E-CD3FE82F5213}><C:\Program Files\Internet Explorer\msvcrt.dll> [N/A]
<{754FB7D8-B8FE-4810-B363-A788CD060F1F}><C:\Program Files\Internet Explorer\PLUGINS\System64.Sys> [N/A]
<jtsa><; C:\DOCUME~1\lkx\LOCALS~1\Temp\jtso.exe> [N/A]


<qjsa><; C:\DOCUME~1\lkx\LOCALS~1\Temp\qjso.exe> [N/A]

<rxsa><; C:\DOCUME~1\lkx\LOCALS~1\Temp\rxso.exe> [N/A]

<tlsa><; C:\DOCUME~1\lkx\LOCALS~1\Temp\tlso.exe> [N/A]
<wdsa><; C:\DOCUME~1\lkx\LOCALS~1\Temp\wdso.exe> [N/A]
<wgsa><; C:\DOCUME~1\lkx\LOCALS~1\Temp\wgso.exe> [N/A]
<wlsa><; C:\DOCUME~1\lkx\LOCALS~1\Temp\wlso.exe> [N/A]
<wmsa><; C:\DOCUME~1\lkx\LOCALS~1\Temp\wmso.exe> [N/A]
<wosa><; C:\DOCUME~1\lkx\LOCALS~1\Temp\woso.exe> [N/A]
<ztsa><; C:\DOCUME~1\lkx\LOCALS~1\Temp\ztso.exe> [N/A]
又这么多
gototop
 

什么意思啊?看不懂
gototop
 

取消启动项:

<regtangtang><C:\WINDOWS\System32\aa.exe> [N/A]
<Microsoft Autorun4><C:\WINDOWS\System32\dllhost32.exe> []
<AVPSrv><C:\WINDOWS\AVPSrv.exe> []
<wosa><C:\DOCUME~1\lkx\LOCALS~1\Temp\woso.exe> [N/A]
<rxsa><C:\DOCUME~1\lkx\LOCALS~1\Temp\rxso.exe> [N/A]
<qjsa><C:\DOCUME~1\lkx\LOCALS~1\Temp\qjso.exe> [N/A]
<tlsa><C:\DOCUME~1\lkx\LOCALS~1\Temp\tlso.exe> [N/A]
<dasa><C:\DOCUME~1\lkx\LOCALS~1\Temp\daso.exe> [N/A]
<wlsa><C:\DOCUME~1\lkx\LOCALS~1\Temp\wlso.exe> [N/A]
<wgsa><C:\DOCUME~1\lkx\LOCALS~1\Temp\wgso.exe> [N/A]

删除插件:
<?{0CD68AC9-FF63-3E61-626B-B663E62F6236}><> [N/A]
<?{0EA66AD2-CF26-2E23-532B-B292E22F3266}><> [N/A]
<{0EA66AD2-CF26-2E23-532B-B292E22F3266}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\NewTemp.dll> [N/A]
<{0EA12C16-CDEF-6AC1-236E-CD3FE82F5213}><C:\Program Files\Internet Explorer\msvcrt.dll> [N/A]
<{754FB7D8-B8FE-4810-B363-A788CD060F1F}><C:\Program Files\Internet Explorer\PLUGINS\System64.Sys> [N/A]
gototop
 

怎么取消,怎么删除啊?我不懂555555555
gototop
 

取消是在前面打钩还是把前面的钩去掉啊?
删除完以后那些被破坏的程序会修复吗?还是要重新安装啊?
gototop
 

对,,你可以用卡卡上网助手来取消.
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT