12   2  /  2  页   跳转

救救可怜的我吧毒死我了!!!!!急

[PID: 3880 / SYSTEM][C:\Program Files\Lenovo\Rescue and Recovery\rrcmd.exe]  [Lenovo Limited Group Corporation, 3,10,17,0]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\jhapri.dll]  [N/A, ]
    [C:\WINDOWS\system32\MFC71CHS.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
[PID: 2592 / SYSTEM][C:\Program Files\Lenovo\Rescue and Recovery\br_funcs.exe]  [Lenovo Group Limited, 3,10,17,0]
    [C:\Program Files\Lenovo\Rescue and Recovery\ui.dll]  [Lenovo Group Limited, 3,10,17,0]
    [C:\Program Files\Lenovo\Rescue and Recovery\CDRecord.dll]  [N/A, ]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Lenovo\Rescue and Recovery\zlib.dll]  [Lenovo Group Limited, 3,10,17,0]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MFC71CHS.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
[PID: 3820 / SYSTEM][C:\Program Files\Rising\Rav\CCenter.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
[PID: 2576 / user][C:\Program Files\Rising\Rav\RavTask.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Unlocker\UnlockerHook.dll]  [N/A, ]
    [C:\WINDOWS\system32\PROCHLP.DLL]  [Lenovo Group Limited, 2, 0, 6, 0]
    [C:\WINDOWS\system32\wlwz3qso.dll]  [N/A, ]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\system32\zeqax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wiytd.dll]  [N/A, ]
    [C:\WINDOWS\system32\wljhj.dll]  [N/A, ]
    [C:\WINDOWS\system32\hytsx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wlkhm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wkjhl.dll]  [N/A, ]
    [C:\WINDOWS\system32\adapi32.dll]  [N/A, ]
[PID: 184 / user][C:\Program Files\Rising\Rav\RsAgent.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\Program Files\Unlocker\UnlockerHook.dll]  [N/A, ]
    [C:\WINDOWS\system32\PROCHLP.DLL]  [Lenovo Group Limited, 2, 0, 6, 0]
    [C:\WINDOWS\system32\wlwz3qso.dll]  [N/A, ]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\system32\zeqax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wiytd.dll]  [N/A, ]
    [C:\WINDOWS\system32\wljhj.dll]  [N/A, ]
    [C:\WINDOWS\system32\hytsx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wlkhm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wkjhl.dll]  [N/A, ]
    [C:\WINDOWS\system32\adapi32.dll]  [N/A, ]
[PID: 3084 / user][C:\WINDOWS\msagent\AgentSvr.exe]  [Microsoft Corporation, 2.00.0.3424]
    [C:\WINDOWS\system32\jhapri.dll]  [N/A, ]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\Program Files\Unlocker\UnlockerHook.dll]  [N/A, ]
    [C:\WINDOWS\system32\PROCHLP.DLL]  [Lenovo Group Limited, 2, 0, 6, 0]
    [C:\WINDOWS\system32\wlwz3qso.dll]  [N/A, ]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\system32\zeqax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wiytd.dll]  [N/A, ]
    [C:\WINDOWS\system32\wljhj.dll]  [N/A, ]
    [C:\WINDOWS\system32\hytsx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wlkhm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wkjhl.dll]  [N/A, ]
    [C:\WINDOWS\system32\adapi32.dll]  [N/A, ]
[PID: 2836 / user][C:\Program Files\Rising\Rav\RAV.EXE]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 36]
    [C:\WINDOWS\system32\jhapri.dll]  [N/A, ]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\Program Files\Rising\Rav\PlugIn\RsPgScan.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 17]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\Rav\RavUI.Dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 30]
    [C:\Program Files\Rising\Rav\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
    [C:\Program Files\Rising\Rav\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [C:\Program Files\Unlocker\UnlockerHook.dll]  [N/A, ]
    [C:\WINDOWS\system32\PROCHLP.DLL]  [Lenovo Group Limited, 2, 0, 6, 0]
    [C:\WINDOWS\system32\wlwz3qso.dll]  [N/A, ]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\system32\zeqax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wiytd.dll]  [N/A, ]
    [C:\WINDOWS\system32\wljhj.dll]  [N/A, ]
    [C:\WINDOWS\system32\hytsx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wlkhm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wkjhl.dll]  [N/A, ]
    [C:\WINDOWS\system32\adapi32.dll]  [N/A, ]
    [C:\Program Files\Rising\Rav\Scanner.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
    [C:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\Program Files\Rising\Rav\libload.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
    [C:\Program Files\Rising\Rav\VirusLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
    [C:\Program Files\Rising\Rav\MVEngine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
    [C:\Program Files\Rising\Rav\Engine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 30]
    [C:\Program Files\Rising\Rav\ScanExec.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
    [C:\Program Files\Rising\Rav\Unpacker.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 22]
    [C:\Program Files\Rising\Rav\UnExe.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [C:\Program Files\Rising\Rav\ScanEx.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 67]
    [C:\Program Files\Rising\Rav\ExtFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 36]
    [C:\Program Files\Rising\Rav\PostTrt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
    [C:\Program Files\Rising\Rav\ScanMac.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
    [C:\Program Files\Rising\Rav\ScanSct.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 20]
    [C:\Program Files\Rising\Rav\ScanPack.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 24]
    [C:\Program Files\Rising\Rav\RsVM.dll]  [, 19, 0, 0, 20]
    [C:\Program Files\Rising\Rav\Uroutine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 45]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [C:\WINDOWS\system32\shlhook.dll]  [Beijing Rising Technology Co., Ltd., 4.0.0.7]
    [C:\Program Files\Rising\Rav\NvFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
    [C:\Program Files\Rising\Rav\ExtMail.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
    [C:\Program Files\Rising\Rav\ExtOLE.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
    [C:\Program Files\Rising\Rav\ScanNet.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\Program Files\Rising\Rav\Uscript.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
    [C:\Program Files\Rising\Rav\RsStore.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [C:\Program Files\Rising\Rav\RsLog.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [C:\Program Files\Rising\Rav\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
gototop
 

[PID: 712 / SYSTEM][C:\Program Files\Rising\Rav\Ravmond.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 49]
    [C:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\Rav\rfwctrl.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
    [C:\Program Files\Rising\Rav\RsPPsys.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\Program Files\Rising\Rav\RsLog.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [C:\Program Files\Rising\Rav\HOOKSYS.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 0]
    [C:\Program Files\Rising\Rav\Scanner.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
    [C:\Program Files\Rising\Rav\libload.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
    [C:\Program Files\Rising\Rav\VirusLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
    [C:\Program Files\Rising\Rav\regmon.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
    [C:\Program Files\Rising\Rav\psapi.dll]  [Microsoft Corporation, 4.00]
    [C:\Program Files\Rising\Rav\HookWeb.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
    [C:\Program Files\Rising\Rav\MemMon.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 14]
    [C:\Program Files\Rising\Rav\expscan.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\Program Files\Rising\Rav\mPorts.dll]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
    [C:\Program Files\Rising\Rav\HookCont.dll]  [Rising, 19, 0, 0, 0]
    [C:\Program Files\Rising\Rav\SpamEng.dll]  [, 18, 0, 0, 6]
    [C:\Program Files\Rising\Rav\engine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 30]
    [C:\Program Files\Rising\Rav\PostTrt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
    [C:\Program Files\Rising\Rav\UnExe.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [C:\Program Files\Rising\Rav\ScanExec.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
    [C:\Program Files\Rising\Rav\ScanEx.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 67]
    [C:\Program Files\Rising\Rav\ExtFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 36]
    [C:\Program Files\Rising\Rav\NvFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
    [C:\Program Files\Rising\Rav\ScanMac.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
    [C:\Program Files\Rising\Rav\ScanSct.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 20]
    [C:\Program Files\Rising\Rav\ScanPack.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 24]
    [C:\Program Files\Rising\Rav\RsVM.dll]  [, 19, 0, 0, 20]
    [C:\Program Files\Rising\Rav\Uroutine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 45]
    [C:\Program Files\Rising\Rav\Uscript.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
    [C:\Program Files\Rising\Rav\RsStore.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [C:\Program Files\Rising\Rav\ExtOLE.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
    [C:\Program Files\Rising\Rav\ScanNet.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[PID: 3404 / user][C:\Program Files\Rising\Rav\RAVMON.EXE]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 45]
    [C:\Program Files\Rising\Rav\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
    [C:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [C:\WINDOWS\system32\jhapri.dll]  [N/A, ]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\Rav\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [C:\Program Files\Rising\Rav\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\Program Files\Unlocker\UnlockerHook.dll]  [N/A, ]
    [C:\WINDOWS\system32\PROCHLP.DLL]  [Lenovo Group Limited, 2, 0, 6, 0]
    [C:\WINDOWS\system32\wlwz3qso.dll]  [N/A, ]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\system32\zeqax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wiytd.dll]  [N/A, ]
    [C:\WINDOWS\system32\wljhj.dll]  [N/A, ]
    [C:\WINDOWS\system32\hytsx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wlkhm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wkjhl.dll]  [N/A, ]
    [C:\WINDOWS\system32\adapi32.dll]  [N/A, ]
[PID: 2904 / SYSTEM][C:\Program Files\Rising\Rav\RavStub.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 3212 / user][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\Program Files\Unlocker\UnlockerHook.dll]  [N/A, ]
    [C:\WINDOWS\system32\PROCHLP.DLL]  [Lenovo Group Limited, 2, 0, 6, 0]
    [C:\PROGRA~1\Google\GOOGLE~1\GOA66E~1.DLL]  [Google, 4.2006.814.1947]
    [C:\Program Files\Google\Google Desktop Search\GoogleDesktopAPI2.dll]  [Google, 4.2006.814.1947]
    [C:\Program Files\Google\Google Desktop Search\GoogleDesktopResources_zh_cn.dll]  [Google, 4.2006.814.1947]
    [C:\WINDOWS\system32\KakaTool.dll]  [Beijing Rising Technology Co., Ltd., 4.0.0.4]
    [c:\program files\google\googletoolbar3.dll]  [Google Inc., 4, 0, 1601, 4978]
    [C:\附件\ComDlls\XunLeiBHO_006.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 3]
    [C:\WINDOWS\System32\DLA\DLASHX_W.DLL]  [Sonic Solutions, 5.20.19a]
    [C:\WINDOWS\system32\DLAAPI_W.DLL]  [Sonic Solutions, 5.20.19a]
    [C:\WINDOWS\System32\DLA\DLACResW.dll]  [Sonic Solutions, 5.20.19a]
    [C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll]  [Sun Microsystems, Inc., 5.0.60.5]
    [C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll]  [Lenovo Group Limited, 2.0.0]
    [C:\Program Files\Lenovo\Client Security Solution\tvt_passwordmanager.dll]  [Lenovo Group Limited, 2.0.0]
    [C:\Program Files\Common Files\Lenovo\tvt_banner.dll]  [Lenovo Group Limited, 1.10.0051.00]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\system32\wiytd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hytsx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wlkhm.dll]  [N/A, ]
    [C:\WINDOWS\system32\adapi32.dll]  [N/A, ]
    [C:\WINDOWS\system32\wkjhl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wljhj.dll]  [N/A, ]
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\system32\mscoree.dll]  [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
    [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll]  [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[PID: 4044 / user][C:\Documents and Settings\user\My Documents\My Music\新建文件夹\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\Program Files\Unlocker\UnlockerHook.dll]  [N/A, ]
    [C:\WINDOWS\system32\PROCHLP.DLL]  [Lenovo Group Limited, 2, 0, 6, 0]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\system32\wiytd.dll]  [N/A, ]
    [C:\WINDOWS\system32\wljhj.dll]  [N/A, ]
    [C:\WINDOWS\system32\hytsx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wlkhm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wkjhl.dll]  [N/A, ]
    [C:\WINDOWS\system32\adapi32.dll]  [N/A, ]
    [C:\Documents and Settings\user\My Documents\My Music\新建文件夹\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
gototop
 

文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
gototop
 

进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1808, C:\PROGRAM FILES\INTEL\WIRELESS\BIN\S24EVMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1964, C:\PROGRAM FILES\LENOVO\RESCUE AND RECOVERY\RRSERVICE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1980, C:\PROGRAM FILES\COMMON FILES\LENOVO\SCHEDULER\TVTSCHED.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 292, C:\PROGRAM FILES\COMMON FILES\LENOVO\LOGGER\LOGMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 340, C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACSVC.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2844, C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\SVCGUIHLPR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3560, C:\PROGRAM FILES\PC CONNECTIVITY SOLUTION\SERVICELAYER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3880, C:\PROGRAM FILES\LENOVO\RESCUE AND RECOVERY\RRCMD.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2592, C:\PROGRAM FILES\LENOVO\RESCUE AND RECOVERY\BR_FUNCS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2576, C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 184, C:\PROGRAM FILES\RISING\RAV\RSAGENT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2836, C:\PROGRAM FILES\RISING\RAV\RAV.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3404, C:\PROGRAM FILES\RISING\RAV\RAVMON.EXE]

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

有好人帮我  的话 请讲详细点谢谢
gototop
 

http://download.rising.com.cn/for_down/kakatool/kakasetupv4.exe下载卡卡上网安全助手4.0
1 运行瑞星卡卡上网安全助手
2 诊断求助=》电脑诊断日志
3 选择"文件详细信息"、"文件名相似分析"2个选项
4 开始扫描=》导出信息,导成txt格式(也可以是htm格式方便自己看,不过论坛不能上传htm格式)
5 把日志中的报告完整拷贝贴上来(附件形式发上来也可以),不要修改(一次发不完请分次发上来)
6 扫日志的时候尽量把不必要的软件关闭 如QQ TM等
7 把扫描出来的可疑文件上传给瑞星http://up.rising.com.cn/webmail/uploadnew.htm
gototop
 

打开SREng-启动项目->注册表->删除以下启动项目
<RAV009B><C:\WINDOWS\system32\RAV009B.exe> [N/A]
<TIMHost><C:\WINDOWS\TIMHost.exe> [N/A]
<Microsoft Autorun4><C:\WINDOWS\system32\dllhost32.exe> []
<{252D2432-37A2-324F-2A54-21BF5CF2F1A2}><C:\WINDOWS\system32\jhapri.dll> []
<{13BA17BC-1B9D-1F8E-2377-27662B472F0D}><C:\WINDOWS\system32\wmgj2qso.dll> [N/A]
<{13BB17BC-1B9D-1F8E-2377-27662B472F0D}><C:\WINDOWS\system32\wlwz3qso.dll> []
<{D8E0E3BA-D55F-4A08-8EE4-0A59E0284124}><C:\WINDOWS\system32\Agent.dll> [N/A]

<AppInit_DLLs><jhapri.dll> []

删除下面的服务(运行SRENG--->启动项目--->服务--->Win32服务应用程序--->选择要删除的服务--->选择删除服务--->点击设置--->出现提示里选择否,确认删除。)
[Applic at ion / WindowsDown][Stopped/Auto Start]
<C:\WINDOWS\system32\servet.exe><N/A>

重启 显示隐藏文件后删除
C:\WINDOWS\system32\servet.exe
C:\WINDOWS\system32\jhapri.dll
C:\WINDOWS\system32\tphklock.dll
[C:\WINDOWS\system32\msdebug.dll] [N/A, ]
[C:\WINDOWS\system32\wlwz3qso.dll] [N/A, ]
[C:\WINDOWS\system32\adapi32.dll] [N/A, ]
[C:\WINDOWS\system32\aetpksw.dll] [N/A, ]
[C:\WINDOWS\system32\wkjhl.dll] [N/A, ]
[C:\WINDOWS\system32\wlkhm.dll] [N/A, ]
[C:\WINDOWS\system32\hytsx.dll] [N/A, ]
[C:\WINDOWS\system32\wljhj.dll] [N/A, ]
[C:\WINDOWS\system32\wiytd.dll] [N/A, ]
[C:\WINDOWS\system32\zeqax.dll] [N/A, ]
C:\WINDOWS\system32\RAV009B.exe
C:\WINDOWS\TIMHost.exe
C:\WINDOWS\system32\dllhost32.exe
C:\WINDOWS\system32\wmgj2qso.dll
C:\WINDOWS\system32\Agent.dll
gototop
 

在安全糢式
1 删除服务
C:\WINDOWS\system32\servet.exe

2  刪除
C:\WINDOWS\system32\RAV009B.exe
C:\WINDOWS\TIMHost.exe
C:\WINDOWS\system32\dllhost32.exe
C:\WINDOWS\system32\jhapri.dll
C:\WINDOWS\system32\wmgj2qso.dll
C:\WINDOWS\system32\wlwz3qso.dll
C:\WINDOWS\system32\Agent.dll
\SystemRoot\system32\DRIVERS\ABP480N5.SYS
C:\WINDOWS\system32\zeqax.dll
C:\WINDOWS\system32\wiytd.dll
C:\WINDOWS\system32\wljhj.dll
C:\WINDOWS\system32\hytsx.dll
C:\WINDOWS\system32\wlkhm.dll
C:\WINDOWS\system32\wkjhl.dll
C:\WINDOWS\system32\aetpksw.dll
C:\WINDOWS\system32\adapi32.dll
C:\WINDOWS\system32\mh104.dll



gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT