12   2  /  2  页   跳转

求助!中毒

[c:\program files\ninetowns corp\icsp_sm\permissionusagelog.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\permissionhardware.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\remotesmswitch.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\projectinstaller.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\downloadresource.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\updatesemaphores.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\unprocessedtaskvo.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\moduleupdate.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\installedmodulevo.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\installedmoduleswrapper.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\invalidsessionexception.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\fileinfo.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\activatedserviceinfo.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\activatedinfo.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\imanagerhandsshaking.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\searchingmanager.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\shelllink.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\currency.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\inetavailable.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\smsearcher.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\standardcolumn.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\standardcolvalue.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\stringwrapper.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\dial.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\servicedistrict.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\modulelist.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\modulefile.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\modulecompare.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\sbwrappercallback.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\servicecategory.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\serviceinfo.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\serviceprivilegemodule.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\serviceversionvo.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\spnotconnectedexception.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\corpinfo.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\broadcastedmessage.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\broadcastedscope.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\isbmsgqueue.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\p2pmessage.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\sbmsgeventargs.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\wrappercallback.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\orderprice.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\ipriceandordermanagementforbuyer.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\iservicesearchingclient.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\smordermanager.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\morder.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\base64type.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\datavalidate.mod]  [N/A, ]
    [c:\program files\ninetowns corp\icsp_sm\servermanager.mod]  [N/A, ]
[PID: 380 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: DNSRV(bld4act)]
    [C:\WINDOWS\system32\kawdbzy.dll]  [N/A, ]
[PID: 2056 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2180 / Admin][F:\Program Files\Rising\Rav\RavTask.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [F:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [F:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [F:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [F:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
[PID: 2196 / Admin][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\kawdbzy.dll]  [N/A, ]
[PID: 2200 / Admin][F:\Program Files\Rising\Rav\Ravmon.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 45]
    [F:\Program Files\Rising\Rav\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
    [F:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [C:\WINDOWS\system32\kawdbzy.dll]  [N/A, ]
    [F:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [F:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [F:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [F:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [F:\Program Files\Rising\Rav\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [F:\Program Files\Rising\Rav\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[PID: 2224 / Admin][C:\Program Files\Ninetowns Corp\iCSP_SM\iProcessAgent.exe]  [ , 1.0.2515.30949]
    [C:\WINDOWS\system32\mscoree.dll]  [Microsoft Corporation, 2.0.50727.253 (QFE.050727-2500)]
    [C:\WINDOWS\system32\kawdbzy.dll]  [N/A, ]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll]  [Microsoft Corporation, 1.1.4322.2407]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll]  [Microsoft Corporation, 1.1.4322.2032]
    [c:\windows\microsoft.net\framework\v1.1.4322\mscorlib.dll]  [Microsoft Corporation, 1.1.4322.2407]
    [c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_8afcce96\mscorlib.dll]  [N/A, ]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll]  [Microsoft Corporation, 1.1.4322.2407]
    [c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll]  [Microsoft Corporation, 1.1.4322.2032]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_f0f32276\system.windows.forms.dll]  [N/A, ]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSCORJIT.DLL]  [Microsoft Corporation, 1.1.4322.2407]
gototop
 

[c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll]  [Microsoft Corporation, 1.1.4322.2407]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_23d66e15\system.dll]  [N/A, ]
    [C:\WINDOWS\system32\netfxperf.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\perfcounter.dll]  [Microsoft Corporation, 1.1.4322.2032]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\CorperfmonExt.dll]  [Microsoft Corporation, 1.1.4322.2407]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll]  [Microsoft Corporation, 1.1.4322.2407]
    [C:\PROGRA~1\MICROS~4\MSSQL\Binn\sqlctr80.dll]  [Microsoft Corporation, 2000.080.0194.00]
    [c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll]  [Microsoft Corporation, 1.1.4322.2032]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_d64706d4\system.drawing.dll]  [N/A, ]
    [c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll]  [Microsoft Corporation, 1.1.4322.2032]
[PID: 2264 / Admin][C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\Program Files\Microsoft SQL Server\80\Tools\Binn\W95SCM.dll]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\Program Files\Microsoft SQL Server\80\Tools\Binn\SQLSVC.dll]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\WINDOWS\system32\odbcbcp.dll]  [Microsoft Corporation, 2000.085.1117.00 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Microsoft SQL Server\80\Tools\Binn\SQLRESLD.dll]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\Program Files\Microsoft SQL Server\80\Tools\Binn\Resources\2052\SQLSVC.RLL]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\Program Files\Microsoft SQL Server\80\Tools\Binn\Resources\2052\sqlmangr.RLL]  [Microsoft Corporation, 2000.080.0194.00]
[PID: 2456 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\System32\kawdbzy.dll]  [N/A, ]
[PID: 3308 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\kawdbzy.dll]  [N/A, ]
[PID: 2952 / Admin][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3584 / Admin][C:\Program Files\Tencent\QQ\QQ.exe]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\QQBaseClassInDll.dll]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\QQHelperDll.dll]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\BasicCtrlDll.dll]  [TENCENT, 7, 0, 431, 1723]
    [C:\Program Files\Tencent\QQ\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\WINDOWS\system32\kawdbzy.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [C:\Program Files\Tencent\QQ\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [C:\Program Files\Tencent\QQ\QQAPI.dll]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [C:\Program Files\Tencent\QQ\LoginCtrl.dll]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\LoginCtrlRes.dll]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\QQRes.dll]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\WizardCtrl.dll]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\QQMainFrame.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\gdiplus.dll]  [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Tencent\QQ\UnReadMsgMgr.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\CQQApplication.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [C:\Program Files\Tencent\QQ\NewSkin.dll]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\MailSummary.dll]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\QQKnowledgeSearch.dll]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\QQAllInOne.dll]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\SCCore.dll]  [TENCENT, 1, 6, 0, 2]
    [C:\Program Files\Tencent\QQ\CameraDll.dll]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\QQSpace.dll]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\vbscript.dll]  [Microsoft Corporation, 5.6.0.7426]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\Program Files\Tencent\QQ\QQGroupMng.dll]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\UserDefinedHead.dll]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\QQPlugin.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\QQConfigPlugin.dll]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\QQAvatar.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\QQCustomFace.dll]  [N/A, ]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Tencent\QQ\QRingMng.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\QQPet.dll]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\LongConnection.dll]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\PhoneAPI.dll]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [C:\Program Files\Tencent\QQ\QQSettingCtrl.dll]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\QQSysMsgMng.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\BQQApplication.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\CommercesMng.dll]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [C:\Program Files\Tencent\QQ\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 310]
    [C:\Program Files\Tencent\QQ\QQSceneMng.dll]  [N/A, ]
    [C:\WINDOWS\system32\mscoree.dll]  [Microsoft Corporation, 2.0.50727.253 (QFE.050727-2500)]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorie.dll]  [Microsoft Corporation, 1.1.4322.2407]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorld.dll]  [Microsoft Corporation, 1.1.4322.2407]
    [C:\Program Files\Tencent\QQ\AddrSearch.dll]  [腾讯科技(深圳)有限公司, 2, 1, 9, 95]
    [C:\Program Files\Tencent\QQ\ImageOle.dll]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\QQLiveQMng.dll]  [TENCENT, 7,0,431,1723]
    [F:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\Program Files\Tencent\QQ\QQDoctor\TSFSCAN.DAT]  [Tencent, 2007, 8, 15, 1]
    [C:\Program Files\Tencent\QQ\GroupConnection.dll]  [TENCENT, 7,0,431,1723]
[PID: 328 / Admin][C:\Program Files\Tencent\QQ\TIMPlatform.exe]  [TENCENT, 7,0,431,1723]
    [C:\Program Files\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 3344 / Admin][F:\Program Files\Rising\Rav\Rav.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 36]
    [C:\WINDOWS\system32\kawdbzy.dll]  [N/A, ]
    [F:\Program Files\Rising\Rav\PlugIn\RsPgScan.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 17]
    [F:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [F:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [F:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [F:\Program Files\Rising\Rav\RavUI.Dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 30]
    [F:\Program Files\Rising\Rav\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
    [F:\Program Files\Rising\Rav\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [F:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [F:\Program Files\Rising\Rav\Scanner.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
    [F:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [C:\WINDOWS\system32\AcSignIcon.dll]  [Autodesk, 16.0.0.86]
    [F:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [F:\Program Files\Rising\Rav\RavQu.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
    [F:\Program Files\Rising\Rav\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[PID: 1980 / Admin][E:\海關資料\soft\sreng2\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [C:\WINDOWS\system32\kawdbzy.dll]  [N/A, ]
    [E:\海關資料\soft\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 2180, F:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2200, F:\PROGRAM FILES\RISING\RAV\RAVMON.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2224, C:\PROGRAM FILES\NINETOWNS CORP\ICSP_SM\IPROCESSAGENT.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2264, C:\PROGRAM FILES\MICROSOFT SQL SERVER\80\TOOLS\BINN\SQLMANGR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2264, C:\PROGRAM FILES\MICROSOFT SQL SERVER\80\TOOLS\BINN\SQLMANGR.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3344, F:\PROGRAM FILES\RISING\RAV\RAV.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3344, F:\PROGRAM FILES\RISING\RAV\RAV.EXE]

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================

[/CODE]
gototop
 

里面那个C:\WINDOWS\system32\kawdbzy.dll这个文件不知可不可以删掉?
gototop
 

这个就是病毒,删掉就好了,后面的日志就这个问题
处理方法:
把C:\WINDOWS\system32\kawdbzy.dll重命名为XXX.XXX
重起删除XXX.XXX
用SRENG删除注册表中
<{28907901-1416-3389-9981-372178569982}><C:\WINDOWS\system32\kawdbzy.dll> []
把[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><kawdbzy.dll> []设置为空
就好了
gototop
 

谢谢!
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT