瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 我又中毒了~55帮我看看日志!重新发的日志

12   2  /  2  页   跳转

我又中毒了~55帮我看看日志!重新发的日志

==================================
正在运行的进程
[PID: 444][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 508][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 532][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\jzfpri.dll]  [N/A, ]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 580][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\jzfpri.dll]  [N/A, ]
    [C:\WINDOWS\System32\LYMANGR.DLL]  [N/A, ]
[PID: 592][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\jzfpri.dll]  [N/A, ]
[PID: 772][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\jzfpri.dll]  [N/A, ]
[PID: 840][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\jzfpri.dll]  [N/A, ]
[PID: 960][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\jzfpri.dll]  [N/A, ]
[PID: 988][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\jzfpri.dll]  [N/A, ]
[PID: 1304][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\system32\jzfpri.dll]  [N/A, ]
[PID: 1444][D:\瑞星\Rising\Rav\RavStub.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
    [D:\瑞星\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [D:\瑞星\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 1672][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\jzfpri.dll]  [N/A, ]
[PID: 1748][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\jzfpri.dll]  [N/A, ]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [C:\WINDOWS\System32\shlhook.dll]  [Beijing Rising Technology Co., Ltd., 4.0.0.7]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\System16.ins]  [N/A, ]
    [C:\WINDOWS\System32\Kvsc32.dll]  [N/A, ]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\卡卡助手\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\System32\nvcpl.dll]  [NVIDIA Corporation, 6.14.10.9147]
    [C:\WINDOWS\System32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.9147]
    [C:\WINDOWS\System32\nvapi.dll]  [N/A, ]
    [C:\WINDOWS\System32\nvshell.dll]  [, ]
    [C:\WINDOWS\System32\ztkpri.dll]  [N/A, ]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [D:\反间谍专家\ske\contmenu.dll]  [N/A, ]
    [D:\瑞星\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\WINDOWS\System32\dhbpri.dll]  [N/A, ]
    [C:\WINDOWS\System32\mppds.dll]  [N/A, ]
    [D:\迅雷\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.2.9]
    [D:\迅雷\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 3, 11]
    [D:\迅雷\Components\ResWorker\DsBho_00.dll]  [, 1, 0, 0, 4]
    [D:\迅雷\Components\ResWorker\DataProcessor_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 6]
    [D:\360安~1\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
[PID: 180][d:\瑞星\rising\rfw\RfwMain.exe]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 72]
    [d:\瑞星\rising\rfw\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
    [d:\瑞星\rising\rfw\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [d:\瑞星\rising\rfw\RfwCtrl.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
    [d:\瑞星\rising\rfw\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [d:\瑞星\rising\rfw\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [D:\卡卡助手\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\System32\mppds.dll]  [N/A, ]
    [C:\WINDOWS\System32\dhbpri.dll]  [N/A, ]
    [C:\WINDOWS\System32\ztkpri.dll]  [N/A, ]
    [C:\WINDOWS\System32\Kvsc32.dll]  [N/A, ]
    [C:\WINDOWS\System32\jzfpri.dll]  [N/A, ]
[PID: 1132][C:\WINDOWS\RTHDCPL.EXE]  [Realtek Semiconductor Corp., 2.0.7.3]
    [C:\WINDOWS\System32\Kvsc32.dll]  [N/A, ]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\卡卡助手\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1696][C:\WINDOWS\System32\RUNDLL32.EXE]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\NvMcTray.dll]  [NVIDIA Corporation, 6.14.10.9147]
    [C:\WINDOWS\System32\nvapi.dll]  [N/A, ]
    [C:\WINDOWS\System32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.9147]
    [D:\卡卡助手\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1928][D:\卡卡助手\runiep.exe]  [Beijing Rising Technology Co., Ltd., 4.0.0.15]
    [D:\卡卡助手\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1264][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3760]
    [D:\卡卡助手\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2084][D:\360安全卫士\360safe\safemon\360Tray.exe]  [奇虎网, 3, 5, 2, 1001]
    [D:\360安全卫士\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [D:\360安全卫士\360safe\safemon\SafeKrnl.dll]  [奇虎网, 3, 5, 0, 1001]
    [D:\360安全卫士\360safe\AntiAdwa.dll]  [360Safe.com, 3, 5, 1, 1001]
    [D:\卡卡助手\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\System32\mppds.dll]  [N/A, ]
    [C:\WINDOWS\System32\dhbpri.dll]  [N/A, ]
    [C:\WINDOWS\System32\ztkpri.dll]  [N/A, ]
    [C:\WINDOWS\System32\Kvsc32.dll]  [N/A, ]
    [C:\WINDOWS\System32\jzfpri.dll]  [N/A, ]
[PID: 2096][C:\WINDOWS\System32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
gototop
 

[D:\卡卡助手\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2300][D:\千千静听\TTPlayer.exe]  [Alen Soft, 5, 0, 1, 0]
    [D:\千千静听\ttpcomm.dll]  [N/A, ]
    [C:\WINDOWS\System32\jzfpri.dll]  [N/A, ]
    [D:\千千静听\ttpres.dll]  [Alen Soft, 5, 0, 1, 0]
    [D:\千千静听\msdmo.dll]  [Microsoft Corporation, 6.03.01.0400]
    [D:\卡卡助手\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\Kvsc32.dll]  [N/A, ]
    [D:\千千静听\AddIn\ttp_lrcsh.dll]  [N/A, ]
    [C:\WINDOWS\System32\mppds.dll]  [N/A, ]
    [C:\WINDOWS\System32\dhbpri.dll]  [N/A, ]
    [C:\WINDOWS\System32\ztkpri.dll]  [N/A, ]
    [D:\千千静听\AddIn\ttp_asf.dll]  [N/A, ]
    [D:\千千静听\AddIn\ttp_aac.dll]  [N/A, ]
    [D:\千千静听\AddIn\ttp_ac3dts.dll]  [N/A, ]
    [D:\千千静听\wmadmod.dll]  [Microsoft Corporation, 10.00.00.3646]
[PID: 2960][C:\WINDOWS\System32\conime.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [D:\卡卡助手\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 3580][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\jzfpri.dll]  [N/A, ]
    [C:\WINDOWS\System32\kakatool.dll]  [Beijing Rising Technology Co., Ltd., 4.0.0.4]
    [D:\迅雷\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.2.9]
    [D:\迅雷\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 3, 11]
    [D:\迅雷\Components\ResWorker\DsBho_00.dll]  [, 1, 0, 0, 4]
    [D:\迅雷\Components\ResWorker\DataProcessor_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 6]
    [D:\360安~1\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [D:\卡卡助手\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\System32\dhbpri.dll]  [N/A, ]
    [C:\WINDOWS\System32\ztkpri.dll]  [N/A, ]
    [C:\WINDOWS\System32\Kvsc32.dll]  [N/A, ]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9c.ocx]  [Adobe Systems, Inc., 9,0,45,0]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\mppds.dll]  [N/A, ]
[PID: 2508][E:\新建文件夹\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\WINDOWS\System32\jzfpri.dll]  [N/A, ]
    [D:\卡卡助手\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\System32\mppds.dll]  [N/A, ]
    [C:\WINDOWS\System32\dhbpri.dll]  [N/A, ]
    [C:\WINDOWS\System32\ztkpri.dll]  [N/A, ]
    [C:\WINDOWS\System32\Kvsc32.dll]  [N/A, ]
gototop
 

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

大家帮帮我呀~~~用瑞星和360杀了后重起又有!!
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT