12   2  /  2  页   跳转

怀疑中招了 ~~`HELP~~

[C:\Program Files\Thunder Network\Thunder\Program\LiveUpdate.dll]  [Thunder Networking Technologies,LTD, 1, 2, 1, 20]
    [C:\Program Files\Thunder Network\Thunder\Components\ExplorerHelper\ExplorerHelper.dll]  [Thunder Networking Technologies,LTD, 1, 0, 4, 15]
    [C:\Program Files\Thunder Network\Thunder\Components\VPSHELL\VPSHELL.dll]  [XunLei, 1, 2, 0, 10]
    [C:\Program Files\Thunder Network\Thunder\Components\UserExperience\UserExperience.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
    [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsXlCom.dll]  [, 1, 0, 0, 16]
    [C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbed10.dll]  [ , 3, 3, 1, 83]
    [C:\Program Files\Thunder Network\Thunder\Program\RegisterDll.dll]  [Thunder Networking Technologies,LTD, 2, 13, 4, 58]
    [C:\Program Files\Thunder Network\Thunder\Program\MSVCIRT.dll]  [Microsoft Corporation, 7.0.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Thunder Network\Thunder\Program\XLNet.Dll]  [Thunder Networking Technologies,LTD, 1, 2, 0, 8]
    [C:\Program Files\Thunder Network\Thunder\Plugins\GouGouTop\GouGouTop.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
    [C:\Program Files\Thunder Network\Thunder\Plugins\BhoAdv\bho_adv.dll]  [深圳市迅雷网络技术有限公司, 1.0.1.0]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 3, 20]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 3, 11]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.2.9]
    [C:\Program Files\Thunder Network\Thunder\Components\VPSHELL\VideoPicture.dll]  [XunLei, 1, 2, 0, 11]
    [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_01.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 6]
    [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\MediaWorker.dll]  [Thunder Networking Technologies,LTD, 1, 2, 0, 18]
[PID: 2336 / sky][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, ]
    [C:\ftc\Filehook.dll]  [Fygsoft and Microsoft, 2.0.0.0]
    [F:\Nokia PC Suite 6\PhoneBrowser.dll]  [Nokia, 6, 81, 46, 1]
    [F:\Nokia PC Suite 6\PCSCM.dll]  [Nokia, 6, 81, 68, 0]
    [C:\WINDOWS\system32\ConnAPI.DLL]  [Nokia., 6, 81, 62, 0]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [F:\Nokia PC Suite 6\Lang\PhoneBrowser_chi-sc.nlr]  [Nokia, 6, 81, 29, 0]
    [F:\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr]  [Nokia, 6, 81, 11, 0]
    [C:\WINDOWS\system32\wpdshext.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\Audiodev.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[PID: 1684 / sky][C:\DOCUME~1\sky\LOCALS~1\Temp\Rar$EX01.593\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [C:\ftc\Filehook.dll]  [Fygsoft and Microsoft, 2.0.0.0]
    [C:\DOCUME~1\sky\LOCALS~1\Temp\Rar$EX01.593\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
gototop
 

文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A
gototop
 

HOSTS 文件
127.0.0.1      localhost
0.0.0.0 182838.com
0.0.0.0 204.177.92.68
0.0.0.0 asiafriendfinder.com
0.0.0.0 asqin123.51.net
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
0.0.0.0 www.jpbeauty.com
0.0.0.0 beautishow.com
0.0.0.0 goodmovies88.com
0.0.0.0 hothack.home.chinaren.com
0.0.0.0 hualiao.net
0.0.0.0 iplus.allyes.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 asqin123.51.net
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
219.153.32.215 auto.search.msn.com

gototop
 

进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1320, C:\PROGRAM FILES\COMMON FILES\SOGOU PXP\P2PSVR.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 1320, C:\PROGRAM FILES\COMMON FILES\SOGOU PXP\P2PSVR.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 468, C:\FTC\TROJANWALL.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 468, C:\FTC\TROJANWALL.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 468, C:\FTC\TROJANWALL.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 3576, C:\PROGRAM FILES\QQ2006\QQ.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3576, C:\PROGRAM FILES\QQ2006\QQ.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3576, C:\PROGRAM FILES\QQ2006\QQ.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 3604, C:\PROGRAM FILES\QQ2006\TIMPLATFORM.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3604, C:\PROGRAM FILES\QQ2006\TIMPLATFORM.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3604, C:\PROGRAM FILES\QQ2006\TIMPLATFORM.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 3184, C:\PROGRAM FILES\TT\TTRAVELER.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3184, C:\PROGRAM FILES\TT\TTRAVELER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3184, C:\PROGRAM FILES\TT\TTRAVELER.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 2516, C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\THUNDER5.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2516, C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\THUNDER5.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2516, C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\THUNDER5.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 2336, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2336, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2336, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
gototop
 

==================================
API HOOK
入口点错误:FreeLibrary (危险等级: 高,  被下面模块所HOOK: 0x5F00002D)

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

==================================
API HOOK
入口点错误:FreeLibrary (危险等级: 高,  被下面模块所HOOK: 0x5F00002D)

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

API HOOK
入口点错误:FreeLibrary (危险等级: 高,  被下面模块所HOOK: 0x5F00002D)

隐藏进程
N/A

[/CODE]
gototop
 

找不到这两个文件
还有 为什么 修复不了这个
"入口点错误:FreeLibrary (危险等级: 高, 被下面模块所HOOK: 0x5F00002D)"
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT