12   2  /  2  页   跳转

急救啊 主页被修改为about.blank.la

文件关联
.TXT  Error. [C:\WINDOWS\notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. [hh.exe %1]
.HLP  Error. [C:\WINDOWS\winhlp32.exe %1]
.INI  Error. [notepad.exe %1]
.INF  Error. [C:\WINDOWS\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
N/A

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 2432, C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2480, C:\PROGRAM FILES\RISING\RAV\RAVMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2712, C:\WINDOWS\SYSTEM32\SAFESIGNCERTREG.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2732, C:\WINDOWS\SYSTEM32\BHDCREGC.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2752, C:\PROGRAM FILES\360SAFE\SAFEMON\360TRAY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2752, C:\PROGRAM FILES\360SAFE\SAFEMON\360TRAY.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2856, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2856, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2972, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2972, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3464, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3464, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 640, C:\PROGRAM FILES\RISING\RAV\RAV.EXE]

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

谁帮我看看日记啊
gototop
 

引用:
【pirong的贴子】谁帮我看看日记啊
………………

[exqhtuuc5l / exqhtuuc5l][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\exqhtuuc5l.sys><N/A>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[npkycryp / npkycryp][Stopped/Manual Start]
<\??\C:\Program Files\Tencent\QQ\npkycryp.sys><N/A>
[SVKP / SVKP][Running/Auto Start]
<\??\C:\WINDOWS\system32\SVKP.sys><AntiCracking>
[81515 / 81515][Running/]
<2 - 系统找不到指定的文件。
><N/A>
用SRENG扫描工具灭掉上面5个驱动程序,手工删除C:\WINDOWS\system32\drivers\exqhtuuc5l.sys、C:\Program Files\Tencent\QQ\npkcrypt.sys、C:\Program Files\Tencent\QQ\npkycryp.sys、C:\WINDOWS\system32\SVKP.sys这4个文件,然后卸载QQ,删除QQ安装目录下的所有文件,重装QQ。

文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.CHM Error. [hh.exe %1]
.HLP Error. [C:\WINDOWS\winhlp32.exe %1]
.INI Error. [notepad.exe %1]
.INF Error. [C:\WINDOWS\NOTEPAD.EXE %1]
用SRENG扫描工具修复以上文件关联。
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT