12   2  /  2  页   跳转

杀不了毒!!!

[C:\Program Files\Tencent\QQ\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\BasicCtrlDll.dll]  [Tencent, 7, 0, 101, 80]
    [C:\Program Files\Tencent\QQ\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 1, 3, 1031]
    [C:\WINDOWS\system32\fkakv.dll]  [Microsoft Corporation, 5, 2, 2265, 3211]
    [c:\progra~1\makb\znxo.dll]  [, 5, 0, 0, 8]
    [C:\WINDOWS\system32\mscomm.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [C:\Program Files\Tencent\QQ\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [C:\Program Files\Tencent\QQ\QQAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [C:\Program Files\Tencent\QQ\LoginCtrl.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\LoginCtrlRes.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQMainFrame.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\CQQApplication.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\NewSkin.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\HostingMgr.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\CameraDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\MailSummary.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQKnowledgeSearch.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\msclibc.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Tencent\QQ\QQAllInOne.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\GroupLive.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\SCCore.dll]  [TENCENT, 2, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\gdiplus.dll]  [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Tencent\QQ\QQSpace.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\vbscript.dll]  [Microsoft Corporation, 5.6.0.7426]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\Program Files\Tencent\QQ\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQSysMsgMng.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQPlugin.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx]  [Adobe Systems, Inc., 9,0,45,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Tencent\QQ\QRingMng.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\QQAvatar.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [C:\Program Files\Tencent\QQ\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [C:\Program Files\Tencent\QQ\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [C:\Program Files\Tencent\QQ\QQPet.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQFileTransfer.dll]  [Tencent, 0, 3, 3, 5]
    [C:\Program Files\Tencent\QQ\QQCustomFace.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
    [C:\Program Files\Tencent\QQ\QQSceneMng.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\BQQApplication.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [C:\Program Files\Tencent\QQ\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 280]
    [C:\Program Files\Tencent\QQ\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 6, 27, 1]
    [C:\Program Files\Tencent\QQ\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [C:\Program Files\Tencent\QQ\CommercesMng.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQPhoneHelper.dll]  [腾讯科技(深圳)有限公司, 2, 1, 9, 95]
    [C:\Program Files\Tencent\QQ\videodevice.dll]  [Tencent, 1, 6, 0, 1]
    [C:\Program Files\Tencent\QQ\inplus.dll]  [Tencent, 1, 6, 0, 0]
    [C:\WINDOWS\system32\l3codeca.acm]  [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
    [C:\Program Files\Tencent\QQ\GroupConnection.dll]  [Tencent, 0, 3, 3, 5]
gototop
 

[PID: 1652 / Administrator][C:\WINDOWS\system32\cmd.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3172 / Administrator][C:\WINDOWS\system32\cmd.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3820 / Administrator][C:\WINDOWS\system32\cmd.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3780 / Administrator][C:\WINDOWS\system32\cmd.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 4064 / Administrator][C:\WINDOWS\system32\cmd.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 4228 / Administrator][C:\Program Files\Tencent\QQ\QZone\Qzone.exe]  [腾讯公司, 1, 9, 103, 20]
    [C:\Program Files\Tencent\QQ\QZone\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 1, 3, 1031]
    [C:\WINDOWS\system32\fkakv.dll]  [Microsoft Corporation, 5, 2, 2265, 3211]
    [c:\progra~1\makb\znxo.dll]  [, 5, 0, 0, 8]
    [c:\progra~1\makb\esct.dll]  [, 5, 0, 0, 8]
    [C:\WINDOWS\system32\msclibc.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\mscomm.dll]  [N/A, ]
[PID: 4124 / Administrator][C:\WINDOWS\system32\cmd.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 4132 / Administrator][C:\WINDOWS\system32\cmd.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 4140 / Administrator][C:\WINDOWS\system32\cmd.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 5968 / Administrator][C:\Program Files\Maxthon2\Maxthon.exe]  [Maxthon International ltd., 2, 0, 2, 2961]
    [C:\Program Files\Maxthon2\mxpp.dll]  [Maxthon, 1, 0, 0, 50]
    [C:\Program Files\Maxthon2\MxSk.dll]  [Maxthon, 1, 0, 0, 119]
    [C:\Program Files\Maxthon2\MxProxy2.dll]  [, 1, 0, 0, 3448]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 1, 3, 1031]
    [C:\WINDOWS\system32\fkakv.dll]  [Microsoft Corporation, 5, 2, 2265, 3211]
    [c:\progra~1\makb\znxo.dll]  [, 5, 0, 0, 8]
    [c:\progra~1\makb\esct.dll]  [, 5, 0, 0, 8]
    [C:\Program Files\Maxthon2\MxFav.dll]  [Maxthon, 1, 0, 0, 212]
    [C:\Program Files\Maxthon2\maxzlib.dll]  [, 1.2.3]
    [C:\Program Files\Maxthon2\mxtool.dll]  [, 1, 0, 0, 7]
    [C:\Program Files\Maxthon2\mxfeedU.dll]  [, 1, 0, 45, 82]
    [C:\WINDOWS\system32\msxml4.dll]  [Microsoft Corporation, 4.20.9818.0]
    [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL]  [Microsoft Corporation, 11.0.5510]
    [C:\WINDOWS\system32\msclibc.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\mscomm.dll]  [N/A, ]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx]  [Adobe Systems, Inc., 9,0,45,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Tencent\QQ\QQPlayerProxy.dll]  [Tencent, 2, 7, 108, 101]
    [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\msxml5.dll]  [Microsoft Corporation, 5.20.1072.0]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll]  [yahoo! china, 3, 4, 3, 1120]
    [C:\Program Files\FlashGet\jccatch.dll]  [www.flashget.com, 1, 8, 4, 1007]
gototop
 

[PID: 4964 / Administrator][C:\WINDOWS\system32\cmd.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 4972 / Administrator][C:\WINDOWS\system32\cmd.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 5532 / Administrator][C:\WINDOWS\system32\cmd.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 4676 / Administrator][C:\WINDOWS\system32\cmd.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 4692 / Administrator][C:\WINDOWS\system32\cmd.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 5796 / Administrator][C:\WINDOWS\system32\cmd.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 4860 / Administrator][C:\WINDOWS\system32\cmd.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 4828 / Administrator][C:\WINDOWS\system32\cmd.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 5636 / Administrator][C:\WINDOWS\system32\cmd.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 5336 / Administrator][C:\WINDOWS\system32\cmd.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 6112 / Administrator][C:\WINDOWS\system32\cmd.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 5676 / Administrator][C:\WINDOWS\system32\cmd.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 5036 / Administrator][C:\WINDOWS\system32\cmd.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 5944 / Administrator][E:\....工作室\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 1, 3, 1031]
    [C:\WINDOWS\system32\fkakv.dll]  [Microsoft Corporation, 5, 2, 2265, 3211]
    [c:\progra~1\makb\znxo.dll]  [, 5, 0, 0, 8]
    [c:\progra~1\makb\esct.dll]  [, 5, 0, 0, 8]
    [E:\.....工作室\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
    [C:\WINDOWS\system32\msclibc.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\mscomm.dll]  [N/A, ]
gototop
 

文件关联
.TXT  Error. [C:\WINDOWS\notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
MSAPI Tcpip [TCP/IP]
    C:\WINDOWS\system32\mscomm.dll(, N/A)

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
N/A

==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 536, C:\WINDOWS\SYSTEM32\83E443C9.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 592, C:\PROGRA~1\YAHOO!\ASSIST~1\YLIVE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 592, C:\PROGRA~1\YAHOO!\ASSIST~1\YLIVE.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 832, C:\WINDOWS\SERVICEPACKFILES\WINLOGON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 832, C:\WINDOWS\SERVICEPACKFILES\WINLOGON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1144, C:\WINDOWS\SYSTEM32\IOUBI.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1884, C:\WINDOWS\SYSTEM32\KKSI8S3.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1884, C:\WINDOWS\SYSTEM32\KKSI8S3.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3232, C:\WINDOWS\SERVICEPACKFILES\FREE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3232, C:\WINDOWS\SERVICEPACKFILES\FREE.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1496, C:\WINDOWS\SYSTEM32\ARCAC.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1496, C:\WINDOWS\SYSTEM32\ARCAC.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2616, C:\PROGRAM FILES\TENCENT\QQ\QQ.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2616, C:\PROGRAM FILES\TENCENT\QQ\QQ.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2808, C:\PROGRAM FILES\TENCENT\QQ\TIMPLATFORM.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2808, C:\PROGRAM FILES\TENCENT\QQ\TIMPLATFORM.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 876, C:\PROGRAM FILES\千千静听绿色增强版\千千静听.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 876, C:\PROGRAM FILES\千千静听绿色增强版\千千静听.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3752, C:\PROGRAM FILES\TENCENT\QQ\QQ.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3752, C:\PROGRAM FILES\TENCENT\QQ\QQ.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 5968, C:\PROGRAM FILES\MAXTHON2\MAXTHON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 5968, C:\PROGRAM FILES\MAXTHON2\MAXTHON.EXE]

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

对不起阿    我这个菜鸟。不知道大家需要哪些资料  就全弄上来了
还有    怎么我的电脑还有残余的雅虎助手  360都开不了了!!!
gototop
 

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<xem><C:\WINDOWS\ServicePackFiles\winlogon.exe> []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<run><C:\WINDOWS\ServicePackFiles\winlogon.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<xem><C:\WINDOWS\ServicePackFiles\winlogon.exe> []


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe webhelp.exe>
==================================
服务
[3ABA2714 / 3ABA2714][Stopped/Auto Start]
<C:\WINDOWS\system32\9D8F8526.EXE -p><N/A>
[9D8F8526 / 9D8F8526][Stopped/Auto Start]
<C:\WINDOWS\system32\50D96B79.EXE -g><Microsoft Corporation>
[A0E91082 / A0E91082][Stopped/Auto Start]
<C:\WINDOWS\system32\EA459ED3.EXE -a><Microsoft Corporation>
[he111p / he111p][Stopped/Auto Start]
<C:\WINDOWS\system32\he111p.exe -service><Microsoft Corporation>
[he1p / he1p][Stopped/Auto Start]
<C:\WINDOWS\system32\he1p.exe -service><N/A>

[husjdd8s / husjdd8s][Stopped/Auto Start]
<C:\WINDOWS\system32\husjdd8s.exe -j><Microsoft Corporation>
[Windows rfpg RunThem / rfpg][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\makb\wkul.dll><>
==================================
驱动程序
[e1x0h / e1x0h][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\e1x0h.sys><N/A>
[idnds / idnds][Running/Boot Start]
<\SystemRoot\system32\drivers\idnds.sys><N/A>
[j0k85nji9 / j0k85nji9][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\j0k85nji9.sys><N/A>
[mssock / mssock][Running/Manual Start]
<\??\C:\WINDOWS\system32\mssock.sys><N/A>

[szydpjc6 / szydpjc6v][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\szydpjc6v.sys><N/A>
==================================
正在运行的进程
[C:\WINDOWS\system32\9D8F8526.DLL] [Microsoft Corporation, ]
[C:\WINDOWS\system32\3779D486.DLL] [Microsoft Corporation, ]
[c:\progra~1\makb\znxo.dll] [, 5, 0, 0, 8]
[c:\progra~1\makb\esct.dll] [, 5, 0, 0, 8]
[C:\WINDOWS\system32\mscomm.dll] [N/A, ]
[C:\WINDOWS\system32\51cs.dll] [N/A, ]

==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.CHM Error. ["hh.exe" %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
==================================
Winsock 提供者
MSAPI Tcpip [TCP/IP]
C:\WINDOWS\system32\mscomm.dll(, N/A)


我个人认为以上有问题。但红色的项目吃不准,提供给高手看看。
个人认为还要用WINSOCKFIX工具来修复。


gototop
 

兄弟们  急啊  救命啊...电脑慢死了!!!

附件附件:

下载次数:208
文件类型:application/octet-stream
文件大小:
上传时间:2007-8-5 20:02:47
描述:



gototop
 

15楼不是给你回复了么
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT