1   1  /  1  页   跳转

求助~~~~~~

求助~~~~~~

各位有那位能帮下忙,最近电脑里出现了种TuFei的病毒
专感染EXE文件的  用瑞星杀了很多次
杀不完  那位能指点下  感激~
最后编辑2006-05-25 22:42:13
分享到:
gototop
 

请下载 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
http://www.kztechs.com/sreng/sreng2.zip
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
日志一次粘不完,分次粘完,不要修改。
gototop
 

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <load><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <NvCplDaemon><; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <RfwMain><"F:\杀毒防黑\rav\Rising\Rfw\rfwmain.exe" -Startup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <IMSCMig><; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <BigDogPath><C:\WINDOWS\VM_STI.EXE PC Camera CAMCAN>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <ExFilter><Rundll32.exe C:\WINDOWS\system32\hookdll.dll,ExecFilter solo>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <RavTask><"F:\杀毒防黑\rav\Rising\Rav\RavTask.exe" -system>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <MSPY2002><; C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <NvMediaCenter><; RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <nwiz><; nwiz.exe /install>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <SoundMan><; SOUNDMAN.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <TkBellExe><; >
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <SysExplr><F:\HeroV8\SysExplr.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
  <BaiduInstall><C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\BaiDu\bar\BDBAR_~1\BaiduBar.dll,Install>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <Userinit><C:\WINDOWS\system32\userinit.exe,,"F:\HFEE\SVOHOST.EXE" un userinit.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <AppInit_DLLs><>

==================================
启动文件夹
服务
[NVIDIA Display Driver Service / NVSvc]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Rising Proxy  Service / RfwProxySrv]
  <f:\杀毒防黑\rav\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService]
  <f:\杀毒防黑\rav\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter]
  <"F:\杀毒防黑\rav\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"F:\杀毒防黑\rav\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>

==================================
浏览器加载项
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v4.dll, >
[BandIE Class]
  {77FEF28E-EB96-44FF-B511-3185DEA48697} <C:\Program Files\BaiDu\bar\BaiduBar.dll, Baidu.com, Inc.>
[NTIECatcher Class]
  {C56CB6B0-0D96-11D6-8C65-B2868B609932} <F:\Net Transport\NTIEHelper.dll, Xi>
[豪杰超级解霸V8]
  {367E0A21-8601-4986-9C9A-153BF5ACA118} <F:\HeroV8\STHSDVD.EXE, herosoft>
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <F:\MICROS~1\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[百度超级搜霸]
  {B580CF65-E151-49C3-B73F-70B13FCA8E86} <C:\Program Files\BaiDu\bar\BaiduBar.dll, Baidu.com, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\flash.ocx, Macromedia, Inc.>
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v4.dll, >
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[XML Document]
  {48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\system32\msxml3.dll, N/A>
[HHCtrl Object]
  {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Windows Media Services DRM Storage object]
  {760C4B83-E211-11D2-BF3E-00805FBE84A6} <C:\WINDOWS\system32\drmstor.dll, Microsoft Corporation>
[BandIE Class]
  {77FEF28E-EB96-44FF-B511-3185DEA48697} <C:\Program Files\BaiDu\bar\BaiduBar.dll, Baidu.com, Inc.>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[百度超级搜霸]
  {B580CF65-E151-49C3-B73F-70B13FCA8E86} <C:\Program Files\BaiDu\bar\BaiduBar.dll, Baidu.com, Inc.>
[NTIECatcher Class]
  {C56CB6B0-0D96-11D6-8C65-B2868B609932} <F:\Net Transport\NTIEHelper.dll, Xi>
[AUDIO__MP3 Moniker Class]
  {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[AUDIO__WAV Moniker Class]
  {CD3AFA7B-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_WMV Moniker Class]
  {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\flash.ocx, Macromedia, Inc.>
[&使用迅雷下载]
  <F:\Thunder\geturl.htm, N/A>
[&使用迅雷下载全部链接]
  <F:\Thunder\getAllurl.htm, N/A>
[Download all by Net Transport]
  <F:\NETTRA~1\NTAddList.html, N/A>
[Download by Net Transport]
  <F:\NETTRA~1\NTAddLink.html, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <F:\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <F:\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <F:\Tencent\QQ\SendMMS.htm, N/A>
[百度-搜索MP3]
  <res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUMP3.HTM, N/A>
[百度-搜索图片]
  <res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUIMG.HTM, N/A>
[百度-搜索新闻]
  <res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUNEWS.HTM, N/A>
[百度-搜索歌词]
  <res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDULYRIC.HTM, N/A>
[百度-搜索网页]
  <res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUSEARCH.HTM, N/A>
[百度-搜索贴吧]
  <res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUPOST.HTM, N/A>
[百度-词典搜索]
  <res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDU_DIC.HTM, N/A>
[豪杰超级解霸V8实时播放]
  <F:\HeroV8\MPURLGET.HTM, N/A>
gototop
 

正在运行的进程
[PID: 372][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 592][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 616][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 660][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 672][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 828][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 872][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 968][F:\杀毒防黑\rav\Rising\Rav\CCenter.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 984][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1108][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1160][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1188][F:\杀毒防黑\rav\Rising\Rav\Ravmond.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 16>
    [F:\杀毒防黑\rav\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [F:\杀毒防黑\rav\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [F:\杀毒防黑\rav\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [F:\杀毒防黑\rav\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [F:\杀毒防黑\rav\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [F:\杀毒防黑\rav\Rising\Rav\RsLog.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
    [F:\杀毒防黑\rav\Rising\Rav\HOOKSYS.dll]  <Rising><18, 1, 0, 9>
    [F:\杀毒防黑\rav\Rising\Rav\Scanner.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
    [F:\杀毒防黑\rav\Rising\Rav\libload.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [F:\杀毒防黑\rav\Rising\Rav\VirusLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [F:\杀毒防黑\rav\Rising\Rav\regmon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [F:\杀毒防黑\rav\Rising\Rav\HookWeb.dll]  <rising><18, 0, 0, 1>
    [F:\杀毒防黑\rav\Rising\Rav\MemMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
    [F:\杀毒防黑\rav\Rising\Rav\expscan.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [F:\杀毒防黑\rav\Rising\Rav\mPorts.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
    [F:\杀毒防黑\rav\Rising\Rav\MailMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [F:\杀毒防黑\rav\Rising\Rav\SpamEng.dll]  <N/A><18, 0, 0, 6>
    [F:\杀毒防黑\rav\Rising\Rav\engine.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
    [F:\杀毒防黑\rav\Rising\Rav\PostTrt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 1408][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [C:\WINDOWS\system32\nvcpl.dll]  <NVIDIA Corporation><6.14.10.5664>
    [C:\WINDOWS\system32\nvshell.dll]  <NVIDIA Corporation><6.14.10.5664>
    [F:\HeroV8\VCvtShell.dll]  <herosoft><1, 0, 0, 1>
    [F:\WinRAR\rarext.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
    [C:\Program Files\BaiDu\bar\BaiduBar.dll]  <Baidu.com, Inc.><2, 0, 2, 62>
    [C:\WINDOWS\system32\xunleibho_v4.dll]  <><4, 3, 2, 29>
    [F:\Net Transport\NTIEHelper.dll]  <Xi><1.40.9>
    [C:\WINDOWS\system32\l3codeca.acm]  <Fraunhofer Institut Integrierte Schaltungen IIS><1, 9, 0, 0305>
[PID: 1448][f:\杀毒防黑\rav\rising\rfw\rfwsrv.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 32>
    [f:\杀毒防黑\rav\rising\rfw\RfwRule.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 13>
    [f:\杀毒防黑\rav\rising\rfw\rfwlog.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
    [f:\杀毒防黑\rav\rising\rfw\Rfwdrv.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
    [f:\杀毒防黑\rav\rising\rfw\MonDrv.dll]  <rs><1, 0, 0, 4>
    [f:\杀毒防黑\rav\rising\rfw\ProcLib.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
[PID: 1656][f:\杀毒防黑\rav\rising\rfw\RfwMain.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 51>
    [f:\杀毒防黑\rav\rising\rfw\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [f:\杀毒防黑\rav\rising\rfw\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [f:\杀毒防黑\rav\rising\rfw\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 1768][C:\WINDOWS\VM_STI.EXE]  <VM.><4.2.610.4>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
[PID: 1856][F:\杀毒防黑\rav\Rising\Rav\RavTask.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [F:\杀毒防黑\rav\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [F:\杀毒防黑\rav\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [F:\杀毒防黑\rav\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [F:\杀毒防黑\rav\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
[PID: 1880][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[PID: 1928][F:\杀毒防黑\rav\Rising\Rav\Ravmon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 16>
    [F:\杀毒防黑\rav\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [F:\杀毒防黑\rav\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [F:\杀毒防黑\rav\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [F:\杀毒防黑\rav\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [F:\杀毒防黑\rav\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [F:\杀毒防黑\rav\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [F:\杀毒防黑\rav\Rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 1948][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 268][C:\WINDOWS\system32\nvsvc32.exe]  <NVIDIA Corporation><6.14.10.5664>
[PID: 400][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2040][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2616][C:\Program Files\Windows Media Player\wmplayer.exe]  <Microsoft Corporation><9.00.00.3250>
    [F:\杀毒防黑\rav\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\l3codeca.acm]  <Fraunhofer Institut Integrierte Schaltungen IIS><1, 9, 0, 0305>
    [C:\Program Files\AC3Filter\ac3filter.ax]  <><0.70b>
[PID: 3900][F:\Tencent\QQ\QQ.exe]  <TENCENT><13, 9, 0, 8214>
    [F:\Tencent\QQ\QQBaseClassInDll.dll]  <><1, 0, 0, 1>
    [F:\Tencent\QQ\QQHelperDll.dll]  <><1, 0, 0, 1>
    [F:\Tencent\QQ\BasicCtrlDll.dll]  <Tencent><0, 3, 0, 5>
    [F:\Tencent\QQ\QQAPI.dll]  <><1, 0, 0, 1>
    [F:\Tencent\QQ\TIMProxy.dll]  <tencent><2.05>
    [F:\Tencent\QQ\HostingMgr.dll]  <><1, 0, 0, 1>
    [F:\Tencent\QQ\LoginCtrl.dll]  <><1, 0, 0, 1>
    [F:\Tencent\QQ\QQRes.dll]  <tencent><1, 0, 0, 1>
    [F:\Tencent\QQ\QQMainFrame.dll]  <N/A><N/A>
    [F:\Tencent\QQ\CQQApplication.dll]  <N/A><N/A>
    [F:\Tencent\QQ\NewSkin.dll]  <><1, 0, 0, 1>
    [F:\Tencent\QQ\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
    [F:\Tencent\QQ\QQAddr.dll]  <深圳市腾讯计算机系统有限公司><0, 3, 0, 36>
    [F:\Tencent\QQ\BQQApplication.dll]  <N/A><N/A>
    [F:\杀毒防黑\rav\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
gototop
 

[F:\Tencent\QQ\VideoDevice.dll]  <Tencent><1.3.8.9>
    [F:\Tencent\QQ\InPlus.dll]  <Tencent><1.3.8.9>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
    [F:\Tencent\QQ\QQPlugin.dll]  <N/A><N/A>
    [F:\Tencent\QQ\QQSpace.dll]  <><1, 0, 0, 1>
    [F:\Tencent\QQ\UserDefinedHead.dll]  <><1, 0, 0, 1>
    [F:\Tencent\QQ\QQAvatar.dll]  <N/A><N/A>
    [F:\Tencent\QQ\FlashAvatarDll.dll]  <><1, 3, 0, 1>
    [F:\Tencent\QQ\QQSysMsgMng.dll]  <N/A><N/A>
    [F:\Tencent\QQ\LongConnection.dll]  <tencent><0, 3, 0, 9>
    [F:\Tencent\QQ\QQConfigPlugin.dll]  <><1, 0, 0, 1>
    [F:\Tencent\QQ\QQPet.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [F:\Tencent\QQ\QRingMng.dll]  <N/A><N/A>
    [F:\Tencent\QQ\QQAllInOne.dll]  <N/A><N/A>
    [F:\Tencent\QQ\CameraDll.dll]  <><1, 0, 0, 1>
    [F:\Tencent\QQ\SCCore.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\macromed\flash\flash.ocx]  <Macromedia, Inc.><6,0,79,0>
    [F:\Tencent\QQ\QQCustomFace.dll]  <N/A><N/A>
    [F:\Tencent\QQGame\GameLogCore.Dll]  <><0, 10, 106, 13>
    [F:\Tencent\QQGame\Core.dll]  <é??úêDìú???????ú?μí3óD?T1???><0, 10, 0, 0>
    [F:\Tencent\QQGame\NetCenter.dll]  <é??úêDìú???????ú?μí3óD?T1???><0, 10, 0, 0>
    [F:\Tencent\QQGame\CmdCenter.dll]  <深圳市腾讯计算机系统有限公司><0, 10, 0, 0>
    [F:\Tencent\QQGame\HelpDll.dll]  <><1, 0, 0, 1>
    [F:\Tencent\QQGame\ResEx.dll]  <深圳市腾讯计算机系统有限公司><0, 10, 0, 0>
    [F:\Tencent\QQGame\GameLogAidMgr.dll]  <><1, 0, 0, 1>
    [F:\Tencent\QQGame\COMToolKit.dll]  <><1, 0, 0, 3>
    [F:\Tencent\QQGame\QQGameAvatar.dll]  <深圳市腾讯计算机系统有限公司                                    Tencent Computer System Ltd.><0, 10, 0, 0>
    [F:\Tencent\QQ\CommercesMng.dll]  <><1, 0, 0, 1>
    [F:\Tencent\QQ\QQSceneMng.dll]  <N/A><N/A>
    [F:\Tencent\QQ\ImageOle.dll]  <TODO: <Company name>><1.0.0.1>
    [F:\Tencent\QQ\QQMagicFace.dll]  <><1, 0, 0, 1>
    [F:\Tencent\QQ\QQUdpGetFileLib.dll]  <tencent><0, 2, 2, 3>
    [C:\WINDOWS\system32\CHENHU4.IME]  <chenhu><5.5>
    [F:\Tencent\QQ\GroupConnection.dll]  <Tencent><0, 3, 0, 5>
[PID: 1252][F:\Tencent\QQ\TIMPlatform.exe]  <tencent><2.05>
    [F:\Tencent\QQ\TIMProxy.dll]  <tencent><2.05>
[PID: 4056][C:\WINDOWS\system32\NOTEPAD.EXE]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3756][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\xunleibho_v4.dll]  <><4, 3, 2, 29>
    [C:\Program Files\BaiDu\bar\BaiduBar.dll]  <Baidu.com, Inc.><2, 0, 2, 62>
    [F:\Net Transport\NTIEHelper.dll]  <Xi><1.40.9>
    [F:\杀毒防黑\rav\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 3744][C:\Documents and Settings\Admin\桌面\SREng.exe]  <Smallfrogs Studio><2.0.12.350>
gototop
 

这项你确定一下F:\HFEE\SVOHOST.EXE。如果你也不知道,建议修复。
运行System Repair Engineer,使用“启动项目,注册表”选中要修复的项HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,,"F:\HFEE\SVOHOST.EXE" un userinit.exe>
点“编辑”在“值”里删除,"F:\HFEE\SVOHOST.EXE" un userinit.exe
ALT+CTRL+DELETE调出任务管理器,终止所有RUNDLL32.EXE 的进程,如果无法终止,请到http://www.onlinedown.net/soft/43974.htm下载诺顿进程管理器终止所有RUNDLL32.EXE 的进程(安装时请注意,在最后一步记得清除安装垃圾软件的选项,默认是选中的)
运行System Repair Engineer,使用“启动项目,注册表”来删除以下选项。
(如果在注册表里无法识别那一下,可以选中一项后,点“编辑”这样会有很明细的路径)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ExFilter><Rundll32.exe C:\WINDOWS\system32\hookdll.dll,ExecFilter solo>
双击我的电脑--工具---文件夹选项--查看--单击选取"显示隐藏文件或文件夹"清除"隐藏受保护的操作系统文件(推荐)"复选框。在提示您确定更改时,单击“是”
删除
F:\HFEE\SVOHOST.EXE
C:\WINDOWS\system32\hookdll.dll

gototop
 

F:\HFEE\SVOHOST.EXE
所谓的“高强度文件夹加密大师”,其实据说完全是个骗人的东西。只不过是把要加密的文件夹移到回收站隐藏起来(设为空文件名或特殊字符的文件名),在原来的位置创建一个同名的rem文件夹,然后当双击这个文件夹时会提示输入密码,输入正确才能打开。只要清空各盘符下的回收站,所有的加密文件全部丢失。用finaldata等软件完全可以看到被放到回收站里的原来的文件夹,把它复制到别的盘符,它就自动解密了。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT